ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317)
Published Mar 19, 2019
7.8
HIGHCVSS 3.1
EPSS 41.59%
Description
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.
Affected products
No data.
Configuration 1
- ≤ 9.26
Configuration 2
- 28
- 29
- 30
Configuration 3
- 14.04
- 16.04
- 18.04
- 18.10
Configuration 4
- 8.0
- 9.0
Configuration 6
- 7.0
- 7.0
- 7.6
- 7.6
- 7.6
- 7.0
No data.
Red Hat Enterprise Linux 7
ghostscript-0:9.07-31.el7_6.9
Fixed · RHSA-2019:0229
Red Hat Enterprise Linux 5
ghostscript
Will not fix
Red Hat Enterprise Linux 6
ghostscript
Will not fix
Red Hat Enterprise Linux 8
ghostscript
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | ghostscript-0:9.07-31.el7_6.9 | Fixed | RHSA-2019:0229 |
| Red Hat Enterprise Linux 5 | ghostscript | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | ghostscript | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | ghostscript | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Important, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Red Hat mitigation
Please refer to the "Mitigation" section of CVE-2018-16509 : https://access.redhat.com/security/cve/cve-2018-16509
No CWE recorded.
References (26)
- http://lists.opensuse.org/opensuse-security-announce/2019-01/msg00047.html x_refsource_CONFIRMMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-01/msg00048.html x_refsource_CONFIRMMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/151307/Ghostscript-Pseudo-Operator-Remote-Code-Execution.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/152367/Slackware-Security-Advisory-ghostscript-Updates.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2019/01/23/5 mailing-listx_refsource_MLISTExploitMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/03/21/1 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/106700 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHBA-2019:0327 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0229 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-6116 Vendor Advisory
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1729 x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory
- https://bugs.ghostscript.com/show_bug.cgi?id=700317 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1666636 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2019/02/msg00016.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6AATIHU32MYKUOXQDJQU4X4DDVL7NAY3/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7N6T5L3SSJX2AVUPHP7GCPATFWUPKZT2/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MWVAVCDXBLPLJMVGNSKGGDTBEOHCJBKK/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVWXVKG72IGEJYHLWE6H3CGALHGFSGGY/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZP34D27RKYV2POJ3NJLSVCHUA5V5C45A/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-6116
- https://seclists.org/bugtraq/2019/Apr/4 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202004-03 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://usn.ubuntu.com/3866-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-6116
- https://www.debian.org/security/2019/dsa-4372 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.exploit-db.com/exploits/46242/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.