Description
A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
References (6)
Scores
CVSS v3
7.8
EPSS
0.0054
EPSS Percentile
67.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-648
CWE-732
Status
published
Products (2)
artifex/ghostscript
9.00 - 9.50
fedoraproject/fedora
31
Published
Nov 27, 2019
Tracked Since
Feb 18, 2026