#VU20470 Permissions, Privileges, and Access Controls in Ghostscript - CVE-2019-14813
Published: August 29, 2019 / Updated: July 18, 2022
Ghostscript
Artifex Software, Inc.
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to unrestricted access to .forceput in setuserparams. A remote attacker can create a specially crafted PDF file, trick the victim to open it and gain access to arbitrary files on the system.