CVE-2019-3838: High severity ghostscript vulnerability
It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
Other sources
The .forceput (or .forcedef depending on the ghostscript version) is still accessible via DefineResource. An attacker could use this flaw to bypass -dSAFER restriction and, for example, have access to the file system outside of the designated restricted directories.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-3838?
CVE-2019-3838 is a vulnerability in the ghostscript software before version 9.27 that allows a specially crafted PostScript file to have access to the file system outside of the constraints imposed by -dSAFER.
How does CVE-2019-3838 affect ghostscript?
CVE-2019-3838 affects ghostscript versions before 9.27.
What is the severity of CVE-2019-3838?
The severity of CVE-2019-3838 is high, with a severity value of 5.5.
How can I fix the CVE-2019-3838 vulnerability?
To fix the CVE-2019-3838 vulnerability, it is recommended to update ghostscript to version 9.27 or later.
Where can I find more information about CVE-2019-3838?
You can find more information about CVE-2019-3838 on the official ghostscript bug tracker at https://bugs.ghostscript.com/show_bug.cgi?id=700576 and the Redhat security advisory at https://access.redhat.com/security/cve/CVE-2018-16509.