Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20108
HistoryMay 16, 2019 - 3:56 a.m.

Remote Code Execution (RCE)

2019-05-1603:56:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.017 Low

EPSS

Percentile

87.8%

Artifex Ghostscript is vulnerable to remote code execution (RCE) vulnerability. This is because the ghostscript could leak sensitive operators on the operand stack when a pseudo-operator pushes a subroutine. A specially crafted PostScript file could use this flaw to escape the -dSAFER protection in order to have access to the file system outside of the SAFER constraints.

References