CVE-2019-10216: High severity ghostscript vulnerability
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass -dSAFER restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-10216?
CVE-2019-10216 is a vulnerability in ghostscript before version 9.50 that enables scripts to bypass `-dSAFER` restrictions and escalate privileges.
What is the severity of CVE-2019-10216?
CVE-2019-10216 has a severity value of 7.8, which is classified as high.
Which software versions are affected by CVE-2019-10216?
Artifex Ghostscript before version 9.50, Redhat 3scale API Management version 2.6, and various versions of Redhat Enterprise Linux are affected by CVE-2019-10216.
How can an attacker exploit CVE-2019-10216?
An attacker can exploit CVE-2019-10216 by creating a specially crafted PostScript file that can escalate privileges and access files outside the intended scope.
Are there any references and additional information about CVE-2019-10216?
Yes, you can find more information about CVE-2019-10216 at the following references: [1] http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=5b85ddd19 [2] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10216 [3] https://security.gentoo.org/glsa/202004-03