CVE-2019-14812: High severity ghostscript vulnerability
A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass -dSAFER restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2019-14812.
What is the severity of CVE-2019-14812?
The severity of CVE-2019-14812 is high, with a severity value of 7.8.
Which versions of ghostscript are affected by CVE-2019-14812?
All ghostscript versions 9.x before 9.50 are affected by CVE-2019-14812.
How can an attacker exploit CVE-2019-14812?
An attacker can exploit CVE-2019-14812 by using a specially crafted PostScript file to disable security protection and gain unauthorized access.
Is there a fix available for CVE-2019-14812?
Yes, a fix is available for CVE-2019-14812. It is recommended to update to ghostscript version 9.50 or later.