CVE-2019-10216

Name
CVE-2019-10216
Description
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10216
Exploit http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=5b85ddd19
Third Party Advisory https://security.gentoo.org/glsa/202004-03

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:* ghostscript >= None < 9.50

Vulnerable and fixed packages

Source package Branch Version Maintainer Status