CVE-2019-14811: High severity ghostscript vulnerability
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfhookDSCCreator procedure where it did not properly secure its privileged calls, enabling scripts to bypass -dSAFER restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-14811?
CVE-2019-14811 is a vulnerability found in ghostscript versions prior to 9.50 that allows scripts to bypass security restrictions.
What is the severity of CVE-2019-14811?
The severity of CVE-2019-14811 is high with a CVSS score of 7.8.
How can I fix CVE-2019-14811?
To fix CVE-2019-14811, update ghostscript to version 9.50 or later.
What is the affected software for CVE-2019-14811?
The affected software for CVE-2019-14811 includes ghostscript versions prior to 9.50, Artifex Ghostscript, Redhat Openshift Container Platform 3.11 and 4.1, Fedoraproject Fedora 29, 30, and 31, openSUSE Leap 15.0 and 15.1, Debian Debian Linux 8.0, 9.0, and 10.0.
Where can I find more information about CVE-2019-14811?
You can find more information about CVE-2019-14811 in the references provided: [1](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00088.html), [2](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00090.html), [3](https://access.redhat.com/errata/RHBA-2019:2824).