Permissions, Privileges, and Access Controls in Ghostscript - CVE-2019-14817
Published: August 29, 2019 / Updated: July 18, 2022
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to unrestricted access to .forceput in setuserparams. A remote attacker can create a specially crafted PDF file, trick the victim to open it and gain access to arbitrary files on the system.
Affected software
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
ghostscript (Alpine package)
ghostscript (Debian package)
ghostscript (Ubuntu package)
ghostscript
How to mitigate CVE-2019-14817
ghostscript (Alpine package) - update to 9.26-r4
ghostscript (Debian package) - addressed in versions 9.26a~dfsg-0+deb9u5, 9.27~dfsg-2+deb10u2
ghostscript (Ubuntu package) - addressed in versions 9.26~dfsg+0-0ubuntu0.16.04.11, 9.26~dfsg+0-0ubuntu0.18.04.11, 9.26~dfsg+0-0ubuntu7.3
ghostscript - addressed in versions 9.27-1.fc29, 9.27-1.fc30, 9.27-1.fc31
External References
Related Security Bulletins
- Security restrictions bypass in Ghostscript
- Ubuntu update for Ghostscript
- Red Hat update for ghostscript
- Red Hat update for ghostscript
- Debian update for ghostscript
- OpenSUSE Linux update for ghostscript
- OpenSUSE Linux update for ghostscript
- Arch Linux update for ghostscript
- Gentoo update for GPL Ghostscript
- Permissions, Privileges, and Access Controls in ghostscript (Alpine package)
- Fedora 29 update for ghostscript
- Fedora 30 update for ghostscript
- Fedora 31 update for ghostscript