Exposed dangerous method or function in Ghostscript - CVE-2019-3835
Published: April 17, 2019
Vulnerability identifier: #VU18288
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3835
CWE-ID: CWE-749
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due presence of superexec operator within the internal dictionary. A remote attacker can create a specially crafted PDF file, trick the victim into opening, bypass system restrictions of the dSAFER sandbox and access files on the system.
Affected software
Ghostscript
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power
Slackware Linux
Opensuse
Fedora
busybox (Alpine package)
ghostscript (Debian package)
ghostscript (Alpine package)
firefox-esr (Alpine package)
ghostscript
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power
Slackware Linux
Opensuse
Fedora
busybox (Alpine package)
ghostscript (Debian package)
ghostscript (Alpine package)
firefox-esr (Alpine package)
ghostscript
How to mitigate CVE-2019-3835
Install updates from vendor's website.
Ghostscript - update to 9.27
ghostscript (Debian package) - update to 9.26a~dfsg-0+deb9u2
ghostscript (Alpine package) - update to 9.26-r2
ghostscript - addressed in versions 9.26-4.fc28, 9.26-4.fc29, 9.26-4.fc30
ghostscript (Debian package) - update to 9.26a~dfsg-0+deb9u2
ghostscript (Alpine package) - update to 9.26-r2
ghostscript - addressed in versions 9.26-4.fc28, 9.26-4.fc29, 9.26-4.fc30
External References
- http://packetstormsecurity.com/files/152367/Slackware-Security-Advisory-ghostscript-Updates.html
- https://access.redhat.com/errata/RHSA-2019:0652
- https://bugs.ghostscript.com/show_bug.cgi?id=700585
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3835
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A43SRQAEHQCKSEMIBINHUNIGHTDCZD7F/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ANBSCZABXQUEQWIKNWJ35IYX24M227EI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SVERLGEU3OV6RNZ2SIBXREWD3BF5H23N/
- https://seclists.org/bugtraq/2019/Apr/4
Related Security Bulletins
- Debian update for ghostscript
- Arch Linux update for ghostscript
- Slackware Linux update for ghostscript
- Red Hat update for ghostscript
- Red Hat update for ghostscript
- OpenSUSE Linux update for ghostscript
- OpenSUSE Linux update for ghostscript
- Gentoo update for GPL Ghostscript
- Exposed dangerous method or function in ghostscript (Alpine package)
- Exposed dangerous method or function in busybox (Alpine package)
- Exposed dangerous method or function in firefox-esr (Alpine package)
- Fedora 28 update for ghostscript
- Fedora 29 update for ghostscript
- Fedora 30 update for ghostscript