FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Ghostscript -- Security bypass vulnerability

Affected packages
ghostscript9-agpl-base < 9.27
ghostscript9-agpl-x11 < 9.27

Details

VuXML ID 5ed7102e-6454-11e9-9a3a-001cc0382b2f
Discovery 2019-03-21
Entry 2019-04-21

Cedric Buissart (Red Hat) reports:

It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

References

CVE Name CVE-2019-3835
CVE Name CVE-2019-3838
URL https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3835
URL https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3838