CVE-2019-3835: High severity ghostscript vulnerability
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
Other sources
The superexec operator is available via either systemdict or internaldict, depending on ghostscript version. An attacker could use this flaw to bypass -dSAFER restrictions and, for example, have access to the file system outside of the designated restricted directories.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3835?
CVE-2019-3835 is a vulnerability in ghostscript that allows a specially crafted PostScript file to have access to the file system.
What is the severity of CVE-2019-3835?
The severity of CVE-2019-3835 is high with a severity value of 5.5.
How does CVE-2019-3835 affect ghostscript?
CVE-2019-3835 affects ghostscript before version 9.27.
How can CVE-2019-3835 be exploited?
CVE-2019-3835 can be exploited by using a specially crafted PostScript file.
Is there a fix for CVE-2019-3835?
Yes, the remedy for CVE-2019-3835 is to upgrade to version 9.27 or later of ghostscript.