ghostscript: superexec operator is available (700585)
Published Mar 25, 2019
5.5
MEDIUMCVSS 3.1
EPSS 2.47%
Description
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
Affected products
-
- Version 9.27StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The ghostscript Project | Ghostscript | n/a |
|
Configuration 1
- < 9.27
Configuration 2
- 3.3
- 7.0
- 7.0
- 7.6
- 7.6
- 7.6
- 7.0
Configuration 3
- 28
- 29
- 30
Configuration 4
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 7
ghostscript-0:9.07-31.el7_6.10
Fixed · RHSA-2019:0633
Red Hat Enterprise Linux 8
ghostscript-0:9.25-2.el8_0.1
Fixed · RHSA-2019:0971
Red Hat Enterprise Linux 5
ghostscript
Will not fix
Red Hat Enterprise Linux 6
ghostscript
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | ghostscript-0:9.07-31.el7_6.10 | Fixed | RHSA-2019:0633 |
| Red Hat Enterprise Linux 8 | ghostscript-0:9.25-2.el8_0.1 | Fixed | RHSA-2019:0971 |
| Red Hat Enterprise Linux 5 | ghostscript | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | ghostscript | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Please refer to the "Mitigation" section of CVE-2018-16509 : https://access.redhat.com/security/cve/cve-2018-16509
References (20)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00088.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00090.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/152367/Slackware-Security-Advisory-ghostscript-Updates.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/107855 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:0652 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0971 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-3835 Vendor Advisory
- https://bugs.ghostscript.com/show_bug.cgi?id=700585 x_refsource_MISCPermissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1677588 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3835 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00021.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A43SRQAEHQCKSEMIBINHUNIGHTDCZD7F/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ANBSCZABXQUEQWIKNWJ35IYX24M227EI/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVERLGEU3OV6RNZ2SIBXREWD3BF5H23N/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-3835
- https://seclists.org/bugtraq/2019/Apr/28 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Apr/4 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202004-03 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-3835
- https://www.debian.org/security/2019/dsa-4432 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.