SB2019091650 - Permissions, Privileges, and Access Controls in ghostscript (Alpine package)
Published: September 16, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-14817)
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to unrestricted access to .forceput in setuserparams. A remote attacker can create a specially crafted PDF file, trick the victim to open it and gain access to arbitrary files on the system.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=3d949953ed023a00e502072af12541c64feb3494
- https://git.alpinelinux.org/aports/commit/?id=743e9bd4848ed6040e641fbe96e145887fd8beb6
- https://git.alpinelinux.org/aports/commit/?id=d523278cd6edc33481e4d0d111f3e2d00ee34033
- https://git.alpinelinux.org/aports/commit/?id=ea68e3cb473042136c9f22682b51d67c84cadba4
- https://git.alpinelinux.org/aports/commit/?id=21ccaac25bfa7e0a4fe100361c0194ba11380604
- https://git.alpinelinux.org/aports/commit/?id=98ae0e5badc623bf92842b4d4c3c5692fd64c081