ghostscript: Multiple Vulnerabilities (CVE-2019-14811, CVE-2019-14812, CVE-2019-14813, CVE-2019-14817)
CVE-2019-14811: Safer mode bypass by .forceput exposure in .pdf_hook_DSC_Creator (701445)
A flaw was found in, ghostscript versions prior to 9.28, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass -dSAFER
restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.References:
References:
- https://www.openwall.com/lists/oss-security/2019/08/28/2
- https://nvd.nist.gov/vuln/detail/CVE-2019-14811
Patch:
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=885444fcbe10dc42787ecb76686c8ee4dd33bf33
Fixed in
- master (47e96eb4)
CVE-2019-14812 : Safer Mode Bypass by .forceput Exposure in setuserparams (701444)
A flaw was found in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass -dSAFER
restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
References:
- https://www.openwall.com/lists/oss-security/2019/08/28/2
- https://bugs.ghostscript.com/show_bug.cgi?id=701444
Patch:
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=885444fcbe10dc42787ecb76686c8ee4dd33bf33
Fixed in
- master (47e96eb4)
CVE-2019-14813 : Safer Mode Bypass by .forceput Exposure in setsystemparams (701443)
A flaw was found in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass -dSAFER
restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
References:
https://www.openwall.com/lists/oss-security/2019/08/28/2 https://bugs.ghostscript.com/show_bug.cgi?id=701443
Patch:
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=885444fcbe10dc42787ecb76686c8ee4dd33bf33
Fixed in
- master (47e96eb4)
CVE-2019-14817 : Safer Mode Bypass by .forceput Exposure in .pdfexectoken and other procedures (701450)
A flaw was found in, ghostscript versions prior to 9.28, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass -dSAFER
restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
References:
- https://www.openwall.com/lists/oss-security/2019/08/28/2
- https://nvd.nist.gov/vuln/detail/CVE-2019-14817
Patch:
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=cd1b1cacadac2479e291efe611979bdc1b3bdb19