VDB

GCVE-VVD-MAGEIA-2019-236

GCVE-VVD-MAGEIA-2019-236
Advisory Published
Vulnetix · Advisory published December 14, 2019
Updated ghostscript packages fix security vulnerability: It was found that the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas (CVE-2019-10216). Also, the Mageia 7 update fixes a bounding box issue that affects klatexformula (mga#24866).

Affected Products

VendorProductVersionsPlatforms
Mageiaghostscript0 (affected), 9.27-1.2.mga7 (unaffected), 0 (affected), 9.27-1.2.mga7 (unaffected)
Mageiaiw0 (affected), 5.4-1.mga7 (unaffected)
Mageiaghostscript0 (affected), 9.26-1.5.mga6 (unaffected), 0 (affected), 9.26-1.5.mga6 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›