Vulnerability CVE-2019-3839


Published: 2019-05-16

Description:
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Debian -> Debian linux 
Artifex -> Ghostscript 

 References:
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=4ec9ca74bed49f2a82acb4bf430eae0d8b3b75c9
https://access.redhat.com/errata/RHSA-2019:0971
https://access.redhat.com/errata/RHSA-2019:1017
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3839
https://lists.debian.org/debian-lts-announce/2019/05/msg00023.html
https://seclists.org/bugtraq/2019/May/23
https://usn.ubuntu.com/3970-1/
https://www.debian.org/security/2019/dsa-4442

Copyright 2020, cxsecurity.com

 

Back to Top