Total vulnerabilities in the database
A flaw was found in all versions of ghostscript 9.x before 9.50, where the .charkeys
procedure, where it did not properly secure its privileged calls, enabling scripts to bypass -dSAFER
restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access files outside of restricted areas or execute commands.
Software | From | Fixed in |
---|---|---|
artifex / ghostscript | 9.00 | 9.50 |
fedoraproject / fedora | 29 | 29.x |
fedoraproject / fedora | 30 | 30.x |
fedoraproject / fedora | 31 | 31.x |
opensuse / leap | 15.0 | 15.0.x |
opensuse / leap | 15.1 | 15.1.x |