Flaw in Ghostscript Enables Bypass of Security Restrictions
CVE-2019-14813
7.3HIGH
What is CVE-2019-14813?
A vulnerability exists in Ghostscript versions prior to 9.50 where the setsystemparams procedure does not adequately secure privileged calls. This flaw allows specially crafted PostScript files to bypass the necessary '-dSAFER' security restrictions, risking unauthorized access to the file system and enabling the execution of arbitrary commands.
Affected Version(s)
ghostscript ghostscript versions 9.x before 9.28