← All CVEs

CVE-2019-14813

critical · 9.8

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

9.8
CVSS
11.4%
EPSS (exploit prob.)
96th
EPSS percentile
2019-09-06
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-648CWE-863

Affected products

VendorProductAffected versions
artifexghostscript>= 9.00, <= 9.50
redhatopenshift_container_platform3.11
redhatopenshift_container_platform4.1
redhatenterprise_linux7.0
redhatenterprise_linux8.0
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_server7.0
redhatenterprise_linux_server_aus7.7
redhatenterprise_linux_server_eus7.7
redhatenterprise_linux_server_tus7.7
redhatenterprise_linux_workstation7.0
fedoraprojectfedora29
fedoraprojectfedora30
fedoraprojectfedora31
opensuseleap15.0
opensuseleap15.1
debiandebian_linux8.0
debiandebian_linux9.0
debiandebian_linux10.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-14813