#VU17230 Command Injection in Ghostscript - CVE-2019-6116
Published: January 27, 2019
Ghostscript
Artifex Software, Inc.
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to leak of sensitive operators on the operand stack when a pseudo-operator pushes a subroutine. A remote unauthenticated attacker can supply a specially crafted PostScript file to escape the -dSAFER protection, gain access to the file system and execute arbitrary commands.