CVE-2019-6116

HIGH

Artifex Ghostscript < 9.26 - Remote Code Execution

Title source: rule

Description

In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textremotelinux
https://www.exploit-db.com/exploits/46242

References (22)

... and 2 more

Scores

CVSS v3 7.8
EPSS 0.6751
EPSS Percentile 98.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

Status published

Affected Products (18)

artifex/ghostscript < 9.26
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux
debian/debian_linux
opensuse/leap
opensuse/leap
redhat/enterprise_linux_desktop
redhat/enterprise_linux_server
redhat/enterprise_linux_server_aus
... and 3 more

Timeline

Published Mar 21, 2019
Tracked Since Feb 18, 2026