CVE-2019-14869

Publication date 14 November 2019

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

8.8 · High

Score breakdown

Description

A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access files outside of restricted areas or execute commands.

Status

Package Ubuntu Release Status
ghostscript 19.10 eoan
Fixed 9.27~dfsg+0-0ubuntu3.1
19.04 disco
Fixed 9.26~dfsg+0-0ubuntu7.4
18.04 LTS bionic
Fixed 9.26~dfsg+0-0ubuntu0.18.04.12
16.04 LTS xenial
Fixed 9.26~dfsg+0-0ubuntu0.16.04.12
14.04 LTS trusty Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
ghostscript

Severity score breakdown

CVSS version: CVSS v3.0

Base score 8.8 · High

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

Related Ubuntu Security Notices (USN)

    • USN-4193-1
    • Ghostscript vulnerability
    • 14 November 2019

Other references


Access our resources on patching vulnerabilities