ghostscript: Safer mode bypass by .forceput exposure in .pdfexectoken and other procedures (701450)
Published Sep 3, 2019
7.8
HIGHCVSS 3.1
EPSS 2.02%
Description
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
Affected products
-
- Version ghostscript versions prior to 9.28StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Artifex Software | Ghostscript | n/a |
|
Configuration 1
- < 9.50
Configuration 2
- 3.11
- 4.1
Configuration 4
- 29
- 30
- 31
Configuration 5
- 8.0
- 9.0
- 10.0
No data.
3scale API Management 2.6 on RHEL 7
3scale-amp26/3scale-operator:1.9-7
Fixed · RHSA-2019:2534
3scale API Management 2.6 on RHEL 7
3scale-amp26/apicast-gateway:1.15-9
Fixed · RHSA-2019:2534
3scale API Management 2.6 on RHEL 7
3scale-amp26/backend:1.9-24
Fixed · RHSA-2019:2534
3scale API Management 2.6 on RHEL 7
3scale-amp26/operator:1.9-7
Fixed · RHSA-2019:2534
3scale API Management 2.6 on RHEL 7
3scale-amp26/toolbox:1.2-5
Fixed · RHSA-2019:2534
3scale API Management 2.6 on RHEL 7
3scale-amp26/zync:1.9-28
Fixed · RHSA-2019:2534
Red Hat Enterprise Linux 7
ghostscript-0:9.25-2.el7_7.2
Fixed · RHSA-2019:2586
Red Hat Enterprise Linux 8
ghostscript-0:9.25-2.el8_0.3
Fixed · RHSA-2019:2591
Red Hat 3scale API Management Platform 2
ghostscript
Not affected
Red Hat Enterprise Linux 5
ghostscript
Out of support scope
Red Hat Enterprise Linux 6
ghostscript
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| 3scale API Management 2.6 on RHEL 7 | 3scale-amp26/3scale-operator:1.9-7 | Fixed | RHSA-2019:2534 |
| 3scale API Management 2.6 on RHEL 7 | 3scale-amp26/apicast-gateway:1.15-9 | Fixed | RHSA-2019:2534 |
| 3scale API Management 2.6 on RHEL 7 | 3scale-amp26/backend:1.9-24 | Fixed | RHSA-2019:2534 |
| 3scale API Management 2.6 on RHEL 7 | 3scale-amp26/operator:1.9-7 | Fixed | RHSA-2019:2534 |
| 3scale API Management 2.6 on RHEL 7 | 3scale-amp26/toolbox:1.2-5 | Fixed | RHSA-2019:2534 |
| 3scale API Management 2.6 on RHEL 7 | 3scale-amp26/zync:1.9-28 | Fixed | RHSA-2019:2534 |
| Red Hat Enterprise Linux 7 | ghostscript-0:9.25-2.el7_7.2 | Fixed | RHSA-2019:2586 |
| Red Hat Enterprise Linux 8 | ghostscript-0:9.25-2.el8_0.3 | Fixed | RHSA-2019:2591 |
| Red Hat 3scale API Management Platform 2 | ghostscript | Not affected | n/a |
| Red Hat Enterprise Linux 5 | ghostscript | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | ghostscript | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (17)
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=cd1b1cacadac2479e291efe611979bdc1b3bdb19 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00088.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00090.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHBA-2019:2824 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2594 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-14817 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1744042 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14817 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00007.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6AATIHU32MYKUOXQDJQU4X4DDVL7NAY3/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LBUC4DBBJTRFNCR3IODBV4IXB2C2HI3V/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZP34D27RKYV2POJ3NJLSVCHUA5V5C45A/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-14817
- https://seclists.org/bugtraq/2019/Sep/15 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202004-03 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14817
- https://www.debian.org/security/2019/dsa-4518 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.