ghostscript: Safer mode bypass by .forceput exposure in setuserparams (701444)
Published Nov 27, 2019
7.8
HIGHCVSS 3.1
EPSS 2.47%
Description
A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
Affected products
-
- Version all ghostscript versions 9.x before 9.50StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Red Hat | Ghostscript | n/a |
|
Configuration 1
- ≥ 9.00 · < 9.50
Configuration 2
- 31
No data.
3scale API Management 2.6 on RHEL 7
3scale-amp26/3scale-operator:1.9-7
Fixed · RHSA-2019:2534
3scale API Management 2.6 on RHEL 7
3scale-amp26/apicast-gateway:1.15-9
Fixed · RHSA-2019:2534
3scale API Management 2.6 on RHEL 7
3scale-amp26/backend:1.9-24
Fixed · RHSA-2019:2534
3scale API Management 2.6 on RHEL 7
3scale-amp26/operator:1.9-7
Fixed · RHSA-2019:2534
3scale API Management 2.6 on RHEL 7
3scale-amp26/toolbox:1.2-5
Fixed · RHSA-2019:2534
3scale API Management 2.6 on RHEL 7
3scale-amp26/zync:1.9-28
Fixed · RHSA-2019:2534
Red Hat Enterprise Linux 7
ghostscript-0:9.25-2.el7_7.2
Fixed · RHSA-2019:2586
Red Hat Enterprise Linux 8
ghostscript-0:9.25-2.el8_0.3
Fixed · RHSA-2019:2591
Red Hat 3scale API Management Platform 2
ghostscript
Not affected
Red Hat Enterprise Linux 5
ghostscript
Out of support scope
Red Hat Enterprise Linux 6
ghostscript
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| 3scale API Management 2.6 on RHEL 7 | 3scale-amp26/3scale-operator:1.9-7 | Fixed | RHSA-2019:2534 |
| 3scale API Management 2.6 on RHEL 7 | 3scale-amp26/apicast-gateway:1.15-9 | Fixed | RHSA-2019:2534 |
| 3scale API Management 2.6 on RHEL 7 | 3scale-amp26/backend:1.9-24 | Fixed | RHSA-2019:2534 |
| 3scale API Management 2.6 on RHEL 7 | 3scale-amp26/operator:1.9-7 | Fixed | RHSA-2019:2534 |
| 3scale API Management 2.6 on RHEL 7 | 3scale-amp26/toolbox:1.2-5 | Fixed | RHSA-2019:2534 |
| 3scale API Management 2.6 on RHEL 7 | 3scale-amp26/zync:1.9-28 | Fixed | RHSA-2019:2534 |
| Red Hat Enterprise Linux 7 | ghostscript-0:9.25-2.el7_7.2 | Fixed | RHSA-2019:2586 |
| Red Hat Enterprise Linux 8 | ghostscript-0:9.25-2.el8_0.3 | Fixed | RHSA-2019:2591 |
| Red Hat 3scale API Management Platform 2 | ghostscript | Not affected | n/a |
| Red Hat Enterprise Linux 5 | ghostscript | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | ghostscript | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Please refer to the "Mitigation" section of CVE-2018-16509 : https://access.redhat.com/security/cve/cve-2018-16509
References (10)
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=885444fcbe10dc42787ecb76686c8ee4dd33bf33 x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2019-14812 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2019-14812 x_refsource_CONFIRMThird Party Advisory
- https://bugs.ghostscript.com/show_bug.cgi?id=701444 x_refsource_CONFIRMPermissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=1743754 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14812 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LBUC4DBBJTRFNCR3IODBV4IXB2C2HI3V/ x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2019-14812
- https://security.gentoo.org/glsa/202004-03 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14812
| Link | Providers | Tags |
|---|---|---|
| http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=885444fcbe10dc42787ecb76686c8ee4dd33bf33 | x_refsource_CONFIRM | |
| https://access.redhat.com/security/cve/CVE-2019-14812 | Vendor Advisory | |
| https://access.redhat.com/security/cve/cve-2019-14812 | x_refsource_CONFIRMThird Party Advisory | |
| https://bugs.ghostscript.com/show_bug.cgi?id=701444 | x_refsource_CONFIRMPermissions Required | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1743754 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14812 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LBUC4DBBJTRFNCR3IODBV4IXB2C2HI3V/ | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-14812 | ||
| https://security.gentoo.org/glsa/202004-03 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-14812 |
Change history (0)
No recorded changes yet.