First published: Thu Feb 07 2019(Updated: )
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Ghostscript | <9.27 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 | |
Fedoraproject Fedora | =29 | |
Fedoraproject Fedora | =30 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =18.10 | |
Canonical Ubuntu Linux | =19.04 | |
Redhat Enterprise Linux | =5.0 | |
Redhat Enterprise Linux | =6.0 | |
redhat/ghostscript | <9.50 | 9.50 |
ubuntu/ghostscript | <9.26~dfsg+0-0ubuntu0.18.04.9 | 9.26~dfsg+0-0ubuntu0.18.04.9 |
ubuntu/ghostscript | <9.26~dfsg+0-0ubuntu0.18.10.9 | 9.26~dfsg+0-0ubuntu0.18.10.9 |
ubuntu/ghostscript | <9.26~dfsg+0-0ubuntu7.1 | 9.26~dfsg+0-0ubuntu7.1 |
ubuntu/ghostscript | <9.27~dfsg-1 | 9.27~dfsg-1 |
ubuntu/ghostscript | <9.26~dfsg+0-0ubuntu0.16.04.9 | 9.26~dfsg+0-0ubuntu0.16.04.9 |
debian/ghostscript | 9.53.3~dfsg-7+deb11u7 10.0.0~dfsg-11+deb12u4 10.03.1~dfsg-2 |
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=4ec9ca74bed49f2a82acb4bf430eae0d8b3b75c9
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=4ec9ca74bed49f2a82acb4bf430eae0d8b3b75c9
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=db24f253409d5d085c2760c814c3e1d3fa2dac59
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-3839.
The severity of CVE-2019-3839 is high with a severity value of 7.8.
The affected software for CVE-2019-3839 includes Ghostscript versions up to and excluding 9.50, Debian Debian Linux 8.0 and 9.0, openSUSE Leap 15.0 and 15.1, Fedoraproject Fedora 29 and 30, and Canonical Ubuntu Linux 16.04, 18.04, 18.10, and 19.04.
To fix CVE-2019-3839, you should update Ghostscript to version 9.50 or later for Red Hat and Artifex Ghostscript, or update to the specified versions for Debian, openSUSE Leap, Fedoraproject Fedora, and Canonical Ubuntu Linux.
You can find more information about CVE-2019-3839 in the provided references: [link1](http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=4ec9ca74bed49f2a82acb4bf430eae0d8b3b75c9), [link2](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00088.html), [link3](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00090.html).