CVE-2019-14813
CRITICALArtifex Ghostscript < 9.50 - Incorrect Authorization
Title source: ruleDescription
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
References (13)
Scores
CVSS v3
9.8
EPSS
0.0845
EPSS Percentile
92.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-648
CWE-863
Status
published
Products (19)
artifex/ghostscript
9.00 - 9.50
debian/debian_linux
8.0
debian/debian_linux
9.0
debian/debian_linux
10.0
fedoraproject/fedora
29
fedoraproject/fedora
30
fedoraproject/fedora
31
opensuse/leap
15.0
opensuse/leap
15.1
redhat/enterprise_linux
7.0
... and 9 more
Published
Sep 06, 2019
Tracked Since
Feb 18, 2026