CVE-2019-6116
published 2019-03-21CVE-2019-6116: In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.
PriorityP263high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
40.80%
98.5th percentile
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 9.27 | 9.27 |
| artifex | ghostscript | <= 9.26 | — |
| artifex | ghostscript | >= 0 < 9.26a~dfsg-1 | 9.26a~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.27~dfsg-1 | 9.27~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.26a~dfsg-1 | 9.26a~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.27~dfsg-1 | 9.27~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.26a~dfsg-1 | 9.26a~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.27~dfsg-1 | 9.27~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.26a~dfsg-1 | 9.26a~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.27~dfsg-1 | 9.27~dfsg-1 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ghostscript | < ghostscript 9.27~dfsg-1 (bookworm) | ghostscript 9.27~dfsg-1 (bookworm) |
| debian | ghostscript | < ghostscript 9.26a~dfsg-1 (bookworm) | ghostscript 9.26a~dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandgs -dSAFER -sDEVICE=ppmraw -sOutputFile=/dev/null -f ghostscript-926-forceput-typecheck-example.ps↗
commandgs -dSAFER -sDEVICE=ppmraw -sOutputFile=/dev/null -f ghostscript-926-forceput-typecheck-executeonly-example.ps↗
- →Detect crafted PostScript files passed to Ghostscript with -dSAFER that attempt to access .forceput or .putgstringcopy operators — these are privileged operators abused in the exploit chain ↗
- →Monitor for Ghostscript invocations processing .ps or .pcd files via downstream applications such as evince, ImageMagick, nautilus, less, gimp, or gv, which can be used as attack vectors ↗
- →Detect PostScript files with .pcd extension delivered via $LESSOPEN, as the default $LESSOPEN can invoke ImageMagick and trigger the exploit ↗
- →Look for PostScript content referencing pdfdict, .forceput, .setglobal, resolvestream, and .pdfruncontext in sequence — these are the staged exploitation primitives used to escape -dSAFER ↗
- →Flag PostScript files that trigger /stackoverflow or /typecheck errors within pseudo-operator context and then attempt operator extraction via error handler inspection ↗
- →Detect use of .putgstringcopy operator in PostScript content — it is a dangerous operator (wrapper around .forceput) that remained accessible after the initial CVE-2019-6116 fix ↗
- ·Ghostscript versions through 9.26 are vulnerable to CVE-2019-6116; the fix was incomplete and residual privileged operator exposure was tracked as CVE-2019-3839, fixed in 9.27 ↗
- ·The exploit requires precise alignment of the operand stack and may need adjustment for versions older than 9.26, but all versions prior to 9.27 are considered affected ↗
- ·The -dSAFER flag does NOT provide effective protection against this vulnerability; exploitation is demonstrated explicitly with -dSAFER enabled ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ghostscript: missing attack vector protections for CVE-2019-6116
vendor_redhat·2019-05-02·CVSS 7.8
CVE-2019-3839 [HIGH] CWE-648 ghostscript: missing attack vector protections for CVE-2019-6116
ghostscript: missing attack vector protections for CVE-2019-6116
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.
It was found that some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
Statement: Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This
Red Hat
ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317)
vendor_redhat·2019-01-23·CVSS 7.8
CVE-2019-6116 [HIGH] ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317)
ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317)
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.
It was found that ghostscript could leak sensitive operators on the operand stack when a pseudo-operator pushes a subroutine. A specially crafted PostScript file could use this flaw to escape the -dSAFER protection in order to, for example, have access to the file system outside of the SAFER constraints.
Statement: Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Important, and is not currently planned to be addressed in future updates. For addit
Ubuntu
Ghostscript vulnerability
vendor_ubuntu·2019-01-23
CVE-2019-6116 Ghostscript vulnerability
Title: Ghostscript vulnerability
Summary: Ghostscript could be made to crash, access files, or run programs if it
opened a specially crafted file.
Tavis Ormandy discovered that Ghostscript incorrectly handled certain
PostScript files. If a user or automated system were tricked into
processing a specially crafted file, a remote attacker could possibly use
this issue to access arbitrary files, execute arbitrary code, or cause a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-3839: ghostscript - It was found that in ghostscript some privileged operators remained accessible f...
vendor_debian·2019·CVSS 7.8
CVE-2019-3839 [HIGH] CVE-2019-3839: ghostscript - It was found that in ghostscript some privileged operators remained accessible f...
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.
Scope: local
bookworm: resolved (fixed in 9.27~dfsg-1)
bullseye: resolved (fixed in 9.27~dfsg-1)
forky: resolved (fixed in 9.27~dfsg-1)
sid: resolved (fixed in 9.27~dfsg-1)
trixie: resolved (fixed in 9.27~dfsg-1)
Debian
CVE-2019-6116: ghostscript - In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow...
vendor_debian·2019·CVSS 7.8
CVE-2019-6116 [HIGH] CVE-2019-6116: ghostscript - In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow...
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.
Scope: local
bookworm: resolved (fixed in 9.26a~dfsg-1)
bullseye: resolved (fixed in 9.26a~dfsg-1)
forky: resolved (fixed in 9.26a~dfsg-1)
sid: resolved (fixed in 9.26a~dfsg-1)
trixie: resolved (fixed in 9.26a~dfsg-1)
GHSA
GHSA-wxr2-p327-97jr: It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2019-3839 [HIGH] CWE-648 GHSA-wxr2-p327-97jr: It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.28 are vulnerable.
GHSA
GHSA-6vrc-h32p-948x: In Artifex Ghostscript through 9
ghsa_unreviewed·2022-05-13
CVE-2019-6116 [HIGH] GHSA-6vrc-h32p-948x: In Artifex Ghostscript through 9
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.
OSV
CVE-2019-3839: It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix
osv·2019-05-16·CVSS 7.8
CVE-2019-3839 [HIGH] CVE-2019-3839: It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.
OSV
CVE-2019-6116: In Artifex Ghostscript through 9
osv·2019-03-21·CVSS 7.8
CVE-2019-6116 [HIGH] CVE-2019-6116: In Artifex Ghostscript through 9
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.
No detection rules found.
Bugzilla
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116 [fedora-all]
bugzilla·2019-09-02·CVSS 7.8
CVE-2019-3839 [HIGH] CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116 [fedora-all]
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116
bugzilla·2019-02-07·CVSS 7.8
CVE-2019-3839 [HIGH] CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116
It was found that some additional operators and dictionaries were needed to be hidden in order to prevent other CVE-2019-6116 attacks.
Discussion:
Mitigation:
Please refer to the "Mitigation" section of CVE-2018-16509 : https://access.redhat.com/security/cve/cve-2018-16509
---
Additional commit required for CVE-2019-6116 :
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=4ec9ca7
+ http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=db24f25 to prevent pdf2dsc regression
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:0971 https://access.redhat.com/errata/RHSA-2019:0971
---
This issue has been addressed in the following products:
Red
Bugzilla
CVE-2019-6116 ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317) [fedora-all]
bugzilla·2019-01-23·CVSS 7.8
CVE-2019-6116 [HIGH] CVE-2019-6116 ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317) [fedora-all]
CVE-2019-6116 ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: thi
Bugzilla
CVE-2019-6116 ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317)
bugzilla·2019-01-16·CVSS 7.8
CVE-2019-6116 [HIGH] CVE-2019-6116 ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317)
CVE-2019-6116 ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317)
It was found that operators did not sufficiently protect their calls to other sensitive operators.
An attacker could use this flaw to get access to sensitive operators, such as .forceput, and use these operators to disable the SAFER mode, and for example, get access to the file system outside of the restricted areas.
Discussion:
Mitigation:
Please refer to the "Mitigation" section of CVE-2018-16509 : https://access.redhat.com/security/cve/cve-2018-16509
---
External References:
https://bugs.ghostscript.com/show_bug.cgi?id=700317
---
Acknowledgments:
Name: Tavis Ormandy (Google Project Zero)
---
Created ghostscript tracking bugs for this issue:
Affects: fedora-all [bug 16
http://lists.opensuse.org/opensuse-security-announce/2019-01/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-01/msg00048.htmlhttp://packetstormsecurity.com/files/151307/Ghostscript-Pseudo-Operator-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/152367/Slackware-Security-Advisory-ghostscript-Updates.htmlhttp://www.openwall.com/lists/oss-security/2019/01/23/5http://www.openwall.com/lists/oss-security/2019/03/21/1http://www.securityfocus.com/bid/106700https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2019:0229https://bugs.chromium.org/p/project-zero/issues/detail?id=1729https://bugs.ghostscript.com/show_bug.cgi?id=700317https://lists.debian.org/debian-lts-announce/2019/02/msg00016.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6AATIHU32MYKUOXQDJQU4X4DDVL7NAY3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7N6T5L3SSJX2AVUPHP7GCPATFWUPKZT2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MWVAVCDXBLPLJMVGNSKGGDTBEOHCJBKK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVWXVKG72IGEJYHLWE6H3CGALHGFSGGY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZP34D27RKYV2POJ3NJLSVCHUA5V5C45A/https://seclists.org/bugtraq/2019/Apr/4https://security.gentoo.org/glsa/202004-03https://usn.ubuntu.com/3866-1/https://www.debian.org/security/2019/dsa-4372https://www.exploit-db.com/exploits/46242/http://lists.opensuse.org/opensuse-security-announce/2019-01/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-01/msg00048.htmlhttp://packetstormsecurity.com/files/151307/Ghostscript-Pseudo-Operator-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/152367/Slackware-Security-Advisory-ghostscript-Updates.htmlhttp://www.openwall.com/lists/oss-security/2019/01/23/5http://www.openwall.com/lists/oss-security/2019/03/21/1http://www.securityfocus.com/bid/106700https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2019:0229https://bugs.chromium.org/p/project-zero/issues/detail?id=1729https://bugs.ghostscript.com/show_bug.cgi?id=700317https://lists.debian.org/debian-lts-announce/2019/02/msg00016.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6AATIHU32MYKUOXQDJQU4X4DDVL7NAY3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7N6T5L3SSJX2AVUPHP7GCPATFWUPKZT2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MWVAVCDXBLPLJMVGNSKGGDTBEOHCJBKK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVWXVKG72IGEJYHLWE6H3CGALHGFSGGY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZP34D27RKYV2POJ3NJLSVCHUA5V5C45A/https://seclists.org/bugtraq/2019/Apr/4https://security.gentoo.org/glsa/202004-03https://usn.ubuntu.com/3866-1/https://www.debian.org/security/2019/dsa-4372https://www.exploit-db.com/exploits/46242/
2019-03-21
Published