Permissions, Privileges, and Access Controls in Ghostscript - CVE-2019-10216

 

Permissions, Privileges, and Access Controls in Ghostscript - CVE-2019-10216

Published: August 12, 2019 / Updated: July 18, 2022


Vulnerability identifier: #VU20059
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10216
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to access arbitrary files on the system.

The vulnerability exists due to an error within the .buildfont1 procedure when making privileged secure calls. A remote attacker can create a specially crafted PostScript file, trick the victim into opening it, bypass the ‘-dSAFER’ restrictions and access arbitrary file on the system.


Affected software

Ghostscript
Gentoo Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux
Opensuse
Fedora
ghostscript (Alpine package)
ghostscript (Ubuntu package)
ghostscript (Debian package)
ghostscript

How to mitigate CVE-2019-10216

Install update from vendor's website.

Ghostscript - update to 9.50
ghostscript (Alpine package) - update to 9.26-r3
ghostscript (Ubuntu package) - addressed in versions 9.26~dfsg+0-0ubuntu0.16.04.10, 9.26~dfsg+0-0ubuntu0.18.04.10, 9.26~dfsg+0-0ubuntu7.2
ghostscript (Debian package) - update to 9.26a~dfsg-0+deb9u4
ghostscript - addressed in versions 9.26-5.fc29, 9.26-5.fc30

External References

Related Security Bulletins