Vulnerability Details CVE-2019-14812
A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.5%
CVSS Severity
CVSS v3 Score 7.3
CVSS v2 Score 6.8
Products affected by CVE-2019-14812
-
cpe:2.3:a:artifex:ghostscript:9.00
-
cpe:2.3:a:artifex:ghostscript:9.01
-
cpe:2.3:a:artifex:ghostscript:9.02
-
cpe:2.3:a:artifex:ghostscript:9.04
-
cpe:2.3:a:artifex:ghostscript:9.05
-
cpe:2.3:a:artifex:ghostscript:9.06
-
cpe:2.3:a:artifex:ghostscript:9.07
-
cpe:2.3:a:artifex:ghostscript:9.09
-
cpe:2.3:a:artifex:ghostscript:9.10
-
cpe:2.3:a:artifex:ghostscript:9.14
-
cpe:2.3:a:artifex:ghostscript:9.15
-
cpe:2.3:a:artifex:ghostscript:9.16
-
cpe:2.3:a:artifex:ghostscript:9.18
-
cpe:2.3:a:artifex:ghostscript:9.19
-
cpe:2.3:a:artifex:ghostscript:9.20
-
cpe:2.3:a:artifex:ghostscript:9.21
-
cpe:2.3:a:artifex:ghostscript:9.22
-
cpe:2.3:a:artifex:ghostscript:9.23
-
cpe:2.3:a:artifex:ghostscript:9.24
-
cpe:2.3:a:artifex:ghostscript:9.25
-
cpe:2.3:a:artifex:ghostscript:9.26
-
cpe:2.3:a:artifex:ghostscript:9.27
-
cpe:2.3:a:artifex:ghostscript:9.28
-
cpe:2.3:o:fedoraproject:fedora:31