Permissions, Privileges, and Access Controls in Ghostscript - CVE-2019-14811
Published: August 29, 2019 / Updated: June 20, 2025
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to unrestricted access to .forceput in .pdf_hook_DSC_Creator. A remote attacker can create a specially crafted PDF file, trick the victim to open it and gain access to arbitrary files on the system.
Affected software
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
ghostscript (Alpine package)
ghostscript (Debian package)
ghostscript (Ubuntu package)
ghostscript
How to mitigate CVE-2019-14811
ghostscript (Alpine package) - update to 9.26-r4
ghostscript (Debian package) - addressed in versions 9.26a~dfsg-0+deb9u5, 9.27~dfsg-2+deb10u2
ghostscript (Ubuntu package) - addressed in versions 9.26~dfsg+0-0ubuntu0.16.04.11, 9.26~dfsg+0-0ubuntu0.18.04.11, 9.26~dfsg+0-0ubuntu7.3
ghostscript - addressed in versions 9.27-1.fc29, 9.27-1.fc30, 9.27-1.fc31
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Security restrictions bypass in Ghostscript
- Ubuntu update for Ghostscript
- Red Hat update for ghostscript
- Red Hat update for ghostscript
- Debian update for ghostscript
- OpenSUSE Linux update for ghostscript
- OpenSUSE Linux update for ghostscript
- Arch Linux update for ghostscript
- Gentoo update for GPL Ghostscript
- Permissions, Privileges, and Access Controls in ghostscript (Alpine package)
- Fedora 29 update for ghostscript
- Fedora 30 update for ghostscript
- Fedora 31 update for ghostscript