CVE-2019-14817
HIGHArtifex Ghostscript < 9.50 - Incorrect Authorization
Title source: ruleDescription
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
References (13)
Scores
CVSS v3
7.8
EPSS
0.0036
EPSS Percentile
58.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-648
CWE-863
Status
published
Products (11)
artifex/ghostscript
< 9.50
debian/debian_linux
8.0
debian/debian_linux
9.0
debian/debian_linux
10.0
fedoraproject/fedora
29
fedoraproject/fedora
30
fedoraproject/fedora
31
opensuse/leap
15.0
opensuse/leap
15.1
redhat/openshift_container_platform
3.11
... and 1 more
Published
Sep 03, 2019
Tracked Since
Feb 18, 2026