cbcvebase.
CVE-2019-6116
published 2019-03-21

CVE-2019-6116: In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EXPLOIT
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
artifexghostscript< 9.279.27
artifexghostscript<= 9.26
artifexghostscript>= 0 < 9.26a~dfsg-19.26a~dfsg-1
artifexghostscript>= 0 < 9.27~dfsg-19.27~dfsg-1
artifexghostscript>= 0 < 9.26a~dfsg-19.26a~dfsg-1
artifexghostscript>= 0 < 9.27~dfsg-19.27~dfsg-1
artifexghostscript>= 0 < 9.26a~dfsg-19.26a~dfsg-1
artifexghostscript>= 0 < 9.27~dfsg-19.27~dfsg-1
artifexghostscript>= 0 < 9.26a~dfsg-19.26a~dfsg-1
artifexghostscript>= 0 < 9.27~dfsg-19.27~dfsg-1
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianghostscript< ghostscript 9.27~dfsg-1 (bookworm)ghostscript 9.27~dfsg-1 (bookworm)
debianghostscript< ghostscript 9.26a~dfsg-1 (bookworm)ghostscript 9.26a~dfsg-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
opensuseleap
opensuseleap
opensuseleap

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH