ghostscript: -dSAFER escape in .charkeys (CVE-2019-14869)ID: oval:org.secpod.oval:def:1802048 | Date: (C)2022-03-25 (M)2023-11-10 |
Class: PATCH | Family: unix |
This is another instance of a highly priviledged operator being accessible by specially crafted Postscript code, that can be used to break out of the -dSAFER limitations. It was found that .forceput operator was present and unprotected in the .charkeys method and could be retrieved via manipulation of the error handler. The .charkeys method was vulnerable since ghostscript-9.15, in one way or another: the privileged operator was superexec instead of .forceput until a more recent version.
Platform: |
Alpine Linux 3.10 |
Alpine Linux 3.11 |
Alpine Linux 3.12 |
Alpine Linux 3.13 |
Alpine Linux 3.14 |
Alpine Linux 3.15 |
Alpine Linux 3.9 |