CVE-2019-25059
published 2022-04-25CVE-2019-25059: Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
PriorityP433high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.12%
62.5th percentile
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | <= 9.26 | — |
| artifex | ghostscript | >= 0 < 9.27~dfsg-1 | 9.27~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.27~dfsg-1 | 9.27~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.27~dfsg-1 | 9.27~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.27~dfsg-1 | 9.27~dfsg-1 |
| debian | debian_linux | — | — |
| debian | ghostscript | < ghostscript 9.27~dfsg-1 (bookworm) | ghostscript 9.27~dfsg-1 (bookworm) |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-77gr-wgqv-qjfm: Artifex Ghostscript through 9
ghsa_unreviewed·2022-04-26·CVSS 7.8
CVE-2019-25059 [HIGH] GHSA-77gr-wgqv-qjfm: Artifex Ghostscript through 9
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
OSV
CVE-2019-25059: Artifex Ghostscript through 9
osv·2022-04-25·CVSS 7.8
CVE-2019-25059 [HIGH] CVE-2019-25059: Artifex Ghostscript through 9
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
Ubuntu
Ghostscript vulnerability
vendor_ubuntu·2022-06-08
CVE-2019-25059 Ghostscript vulnerability
Title: Ghostscript vulnerability
Summary: Ghostscript could be made to crash, access files, or run programs if it
opened a specially crafted file.
USN-5396-1 addressed a vulnerability in Ghostscript. This update
provides the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Ghostscript incorrectly handled certain PostScript
files. If a user or automated system were tricked into processing a
specially crafted file, a remote attacker could possibly use this issue to
access arbitrary files, execute arbitrary code, or cause a denial of
service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Ghostscript vulnerability
vendor_ubuntu·2022-04-28
CVE-2019-25059 Ghostscript vulnerability
Title: Ghostscript vulnerability
Summary: Ghostscript could be made to crash, access files, or run programs if it
opened a specially crafted file.
It was discovered that Ghostscript incorrectly handled certain PostScript
files. If a user or automated system were tricked into processing a
specially crafted file, a remote attacker could possibly use this issue to
access arbitrary files, execute arbitrary code, or cause a denial of
service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ghostscript: Mishandling of .completefont (incomplete fix for CVE-2019-3839)
vendor_redhat·2022-04-25·CVSS 7.8
CVE-2019-25059 [HIGH] CWE-1173 ghostscript: Mishandling of .completefont (incomplete fix for CVE-2019-3839)
ghostscript: Mishandling of .completefont (incomplete fix for CVE-2019-3839)
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
Package: ghostscript (Red Hat Enterprise Linux 6) - Not affected
Package: ghostscript (Red Hat Enterprise Linux 7) - Not affected
Package: ghostscript (Red Hat Enterprise Linux 8) - Will not fix
Package: gimp:flatpak/ghostscript (Red Hat Enterprise Linux 8) - Will not fix
Package: ghostscript (Red Hat Enterprise Linux 9) - Will not fix
Debian
CVE-2019-25059: ghostscript - Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exis...
vendor_debian·2019·CVSS 7.8
CVE-2019-25059 [HIGH] CVE-2019-25059: ghostscript - Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exis...
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
Scope: local
bookworm: resolved (fixed in 9.27~dfsg-1)
bullseye: resolved (fixed in 9.27~dfsg-1)
forky: resolved (fixed in 9.27~dfsg-1)
sid: resolved (fixed in 9.27~dfsg-1)
trixie: resolved (fixed in 9.27~dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=430e219ea17a2650577d70021399c4ead05869e0https://lists.debian.org/debian-lts-announce/2022/05/msg00000.htmlhttp://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=430e219ea17a2650577d70021399c4ead05869e0https://lists.debian.org/debian-lts-announce/2022/05/msg00000.html
2022-04-25
Published