Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

Mageia 6 and 7 Security Notice: Critical Ghostscript Safer Mode Bypass

mageia
Calendar Grey September 12, 2019
Scroller Mageia
Enhanced ghostscript updates for Mageia address significant security vulnerabilities concerning Safer Mode Bypass exploits.
The updated packages fix security vulnerabilities: Safer Mode Bypass by .forceput Exposure in .pdf_hook_DSC_Creator

Summary

The updated packages fix security vulnerabilities:
Safer Mode Bypass by .forceput Exposure in .pdf_hook_DSC_Creator. (CVE-2019-14811)
Safer Mode Bypass by .forceput Exposure in setuserparams. (CVE-2019-14812)
Safer Mode Bypass by .forceput Exposure in setsystemparams. (CVE-2019-14813)
Safer Mode Bypass by .forceput Exposure in .pdfexectoken and other procedures. (CVE-2019-14817)

References

- https://bugs.mageia.org/show_bug.cgi?id=25379

- https://www.openwall.com/lists/oss-security/2019/08/28/2

- https://access.redhat.com/errata/RHSA-2019:2586

- https://www.cve.org/CVERecord?id=CVE-2019-14811

- https://www.cve.org/CVERecord?id=CVE-2019-14812

- https://www.cve.org/CVERecord?id=CVE-2019-14813

Resolution

SRPMS

- 7/core/ghostscript-9.27-1.3.mga7

- 6/core/ghostscript-9.26-1.6.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 12 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0271.html
Type: security
CVE: CVE-2019-14811, CVE-2019-14812, CVE-2019-14813

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.