CVE-2019-3839
published 2019-05-16CVE-2019-3839: It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.76%
75.4th percentile
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 9.27 | 9.27 |
| artifex | ghostscript | <= 9.26 | — |
| artifex | ghostscript | >= 0 < 9.27~dfsg-1 | 9.27~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.27~dfsg-1 | 9.27~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.27~dfsg-1 | 9.27~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.27~dfsg-1 | 9.27~dfsg-1 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ghostscript | < ghostscript 9.27~dfsg-1 (bookworm) | ghostscript 9.27~dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| the_ghostscript_project | ghostscript | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.3HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wxr2-p327-97jr: It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2019-3839 [HIGH] CWE-648 GHSA-wxr2-p327-97jr: It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.28 are vulnerable.
GHSA
GHSA-77gr-wgqv-qjfm: Artifex Ghostscript through 9
ghsa_unreviewed·2022-04-26·CVSS 7.8
CVE-2019-25059 [HIGH] GHSA-77gr-wgqv-qjfm: Artifex Ghostscript through 9
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
OSV
CVE-2019-25059: Artifex Ghostscript through 9
osv·2022-04-25·CVSS 7.8
CVE-2019-25059 [HIGH] CVE-2019-25059: Artifex Ghostscript through 9
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
OSV
CVE-2019-3839: It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix
osv·2019-05-16·CVSS 7.8
CVE-2019-3839 [HIGH] CVE-2019-3839: It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.
Red Hat
ghostscript: Mishandling of .completefont (incomplete fix for CVE-2019-3839)
vendor_redhat·2022-04-25·CVSS 7.8
CVE-2019-25059 [HIGH] CWE-1173 ghostscript: Mishandling of .completefont (incomplete fix for CVE-2019-3839)
ghostscript: Mishandling of .completefont (incomplete fix for CVE-2019-3839)
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
Package: ghostscript (Red Hat Enterprise Linux 6) - Not affected
Package: ghostscript (Red Hat Enterprise Linux 7) - Not affected
Package: ghostscript (Red Hat Enterprise Linux 8) - Will not fix
Package: gimp:flatpak/ghostscript (Red Hat Enterprise Linux 8) - Will not fix
Package: ghostscript (Red Hat Enterprise Linux 9) - Will not fix
Ubuntu
Ghostscript vulnerability
vendor_ubuntu·2019-05-08
CVE-2019-3839 Ghostscript vulnerability
Title: Ghostscript vulnerability
Summary: Ghostscript could be made to crash, access files, or run programs if it
opened a specially crafted file.
It was discovered that Ghostscript incorrectly handled certain PostScript
files. If a user or automated system were tricked into processing a
specially crafted file, a remote attacker could possibly use this issue to
access arbitrary files, execute arbitrary code, or cause a denial of
service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ghostscript: missing attack vector protections for CVE-2019-6116
vendor_redhat·2019-05-02·CVSS 7.8
CVE-2019-3839 [HIGH] CWE-648 ghostscript: missing attack vector protections for CVE-2019-6116
ghostscript: missing attack vector protections for CVE-2019-6116
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.
It was found that some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
Statement: Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This
Debian
CVE-2019-25059: ghostscript - Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exis...
vendor_debian·2019·CVSS 7.8
CVE-2019-25059 [HIGH] CVE-2019-25059: ghostscript - Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exis...
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
Scope: local
bookworm: resolved (fixed in 9.27~dfsg-1)
bullseye: resolved (fixed in 9.27~dfsg-1)
forky: resolved (fixed in 9.27~dfsg-1)
sid: resolved (fixed in 9.27~dfsg-1)
trixie: resolved (fixed in 9.27~dfsg-1)
Debian
CVE-2019-3839: ghostscript - It was found that in ghostscript some privileged operators remained accessible f...
vendor_debian·2019·CVSS 7.8
CVE-2019-3839 [HIGH] CVE-2019-3839: ghostscript - It was found that in ghostscript some privileged operators remained accessible f...
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.
Scope: local
bookworm: resolved (fixed in 9.27~dfsg-1)
bullseye: resolved (fixed in 9.27~dfsg-1)
forky: resolved (fixed in 9.27~dfsg-1)
sid: resolved (fixed in 9.27~dfsg-1)
trixie: resolved (fixed in 9.27~dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116 [fedora-all]
bugzilla·2019-09-02·CVSS 7.8
CVE-2019-3839 [HIGH] CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116 [fedora-all]
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116
bugzilla·2019-02-07·CVSS 7.8
CVE-2019-3839 [HIGH] CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116
It was found that some additional operators and dictionaries were needed to be hidden in order to prevent other CVE-2019-6116 attacks.
Discussion:
Mitigation:
Please refer to the "Mitigation" section of CVE-2018-16509 : https://access.redhat.com/security/cve/cve-2018-16509
---
Additional commit required for CVE-2019-6116 :
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=4ec9ca7
+ http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=db24f25 to prevent pdf2dsc regression
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:0971 https://access.redhat.com/errata/RHSA-2019:0971
---
This issue has been addressed in the following products:
Red
http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=4ec9ca74bed49f2a82acb4bf430eae0d8b3b75c9http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00088.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00090.htmlhttps://access.redhat.com/errata/RHSA-2019:0971https://access.redhat.com/errata/RHSA-2019:1017https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3839https://lists.debian.org/debian-lts-announce/2019/05/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6AATIHU32MYKUOXQDJQU4X4DDVL7NAY3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZP34D27RKYV2POJ3NJLSVCHUA5V5C45A/https://seclists.org/bugtraq/2019/May/23https://usn.ubuntu.com/3970-1/https://www.debian.org/security/2019/dsa-4442http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=4ec9ca74bed49f2a82acb4bf430eae0d8b3b75c9http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00088.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00090.htmlhttps://access.redhat.com/errata/RHSA-2019:0971https://access.redhat.com/errata/RHSA-2019:1017https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3839https://lists.debian.org/debian-lts-announce/2019/05/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6AATIHU32MYKUOXQDJQU4X4DDVL7NAY3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZP34D27RKYV2POJ3NJLSVCHUA5V5C45A/https://seclists.org/bugtraq/2019/May/23https://usn.ubuntu.com/3970-1/https://www.debian.org/security/2019/dsa-4442
2019-05-16
Published