ISOMAN

CVE

CVE-2019-6116

In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

Severity
HIGH
CVSS
7.8
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2019-01/msg00047.html
  2. http://lists.opensuse.org/opensuse-security-announce/2019-01/msg00048.html
  3. http://packetstormsecurity.com/files/151307/Ghostscript-Pseudo-Operator-Remote-Code-Execution.html
  4. http://packetstormsecurity.com/files/152367/Slackware-Security-Advisory-ghostscript-Updates.html
  5. http://www.openwall.com/lists/oss-security/2019/01/23/5
  6. http://www.openwall.com/lists/oss-security/2019/03/21/1
  7. http://www.securityfocus.com/bid/106700
  8. https://access.redhat.com/errata/RHBA-2019:0327
  9. https://access.redhat.com/errata/RHSA-2019:0229
  10. https://bugs.chromium.org/p/project-zero/issues/detail?id=1729
  11. https://bugs.ghostscript.com/show_bug.cgi?id=700317
  12. https://lists.debian.org/debian-lts-announce/2019/02/msg00016.html
  13. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6AATIHU32MYKUOXQDJQU4X4DDVL7NAY3/
  14. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7N6T5L3SSJX2AVUPHP7GCPATFWUPKZT2/
  15. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MWVAVCDXBLPLJMVGNSKGGDTBEOHCJBKK/
  16. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVWXVKG72IGEJYHLWE6H3CGALHGFSGGY/
  17. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZP34D27RKYV2POJ3NJLSVCHUA5V5C45A/
  18. https://seclists.org/bugtraq/2019/Apr/4
  19. https://security.gentoo.org/glsa/202004-03
  20. https://usn.ubuntu.com/3866-1/