VDB

GCVE-VVD-MAGEIA-2019-130

GCVE-VVD-MAGEIA-2019-130
Advisory Published
Vulnetix · Advisory published September 21, 2019
It was found that the superexec operator was available in the internal dictionary. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. (CVE-2019-3835) It was found that the forceput operator could be extracted from the DefineResource method using methods similar to the ones described in CVE-2019-6116. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constraints imposed by -dSAFER. (CVE-2019-3838)

Affected Products

VendorProductVersionsPlatforms
Mageiadrakconf0 (affected), 13.22-1.mga7 (unaffected)
Mageiaghostscript0 (affected), 9.26-1.3.mga6 (unaffected), 0 (affected), 9.26-1.3.mga6 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›