OPENSUSE-SU-2019:2223-1

Advisory lineage Upstream: 7 Downstream: 0
Published: 30 Sept 2019, 14:23
Last modified:04 Feb 2026, 03:32

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Sept 2019, 14:23
Published
Vulnerability first disclosed
04 Feb 2026, 03:32
Last Modified
Vulnerability information updated

Description

Security update for ghostscript This update for ghostscript fixes the following issues: Security issues fixed: - CVE-2019-3835: Fixed an unauthorized file system access caused by an available superexec operator. (bsc#1129180) - CVE-2019-3839: Fixed an unauthorized file system access caused by available privileged operators. (bsc#1134156) - CVE-2019-12973: Fixed a denial-of-service vulnerability in the OpenJPEG function opj_t1_encode_cblks. (bsc#1140359) - CVE-2019-14811: Fixed a safer mode bypass by .forceput exposure in .pdf_hook_DSC_Creator. (bsc#1146882) - CVE-2019-14812: Fixed a safer mode bypass by .forceput exposure in setuserparams. (bsc#1146882) - CVE-2019-14813: Fixed a safer mode bypass by .forceput exposure in setsystemparams. (bsc#1146882) - CVE-2019-14817: Fixed a safer mode bypass by .forceput exposure in .pdfexectoken and other procedures. (bsc#1146884) This update was imported from the SUSE:SLE-15:Update update project.

Affected Systems

  • opensuseghostscript-mini&distro=openSUSE Leap 15.1

    < 9.27-lp151.3.6.1

  • opensuseghostscript&distro=openSUSE Leap 15.1

    < 9.27-lp151.3.6.1

References (14)