Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-3838
Description:It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
Test IDs: 1.3.6.1.4.1.25623.1.0.852372   1.3.6.1.4.1.25623.1.0.852354   1.3.6.1.4.1.25623.1.1.2.2019.1364   1.3.6.1.4.1.25623.1.1.4.2019.0719.1   1.3.6.1.4.1.25623.1.1.4.2019.14155.1   1.3.6.1.4.1.25623.1.1.4.2019.0718.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-3838
Bugtraq: 20190402 [slackware-security] ghostscript (SSA:2019-092-01) (Google Search)
https://seclists.org/bugtraq/2019/Apr/4
Bugtraq: 20190417 [SECURITY] [DSA 4432-1] ghostscript security update (Google Search)
https://seclists.org/bugtraq/2019/Apr/28
Debian Security Information: DSA-4432 (Google Search)
https://www.debian.org/security/2019/dsa-4432
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ANBSCZABXQUEQWIKNWJ35IYX24M227EI/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A43SRQAEHQCKSEMIBINHUNIGHTDCZD7F/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SVERLGEU3OV6RNZ2SIBXREWD3BF5H23N/
https://security.gentoo.org/glsa/202004-03
http://packetstormsecurity.com/files/152367/Slackware-Security-Advisory-ghostscript-Updates.html
https://bugs.ghostscript.com/show_bug.cgi?id=700576
https://lists.debian.org/debian-lts-announce/2019/04/msg00021.html
RedHat Security Advisories: RHSA-2019:0652
https://access.redhat.com/errata/RHSA-2019:0652
RedHat Security Advisories: RHSA-2019:0971
https://access.redhat.com/errata/RHSA-2019:0971
SuSE Security Announcement: openSUSE-SU-2019:1119 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00011.html
SuSE Security Announcement: openSUSE-SU-2019:1121 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00018.html




© 1998-2024 E-Soft Inc. All rights reserved.