VDB
GCVE-VVD-MAGEIA-2019-236
GCVE-VVD-MAGEIA-2019-236
Advisory Published
Updated ghostscript packages fix security vulnerability:
It was found that the .buildfont1 procedure did not properly secure its
privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An
attacker could abuse this flaw by creating a specially crafted PostScript
file that could escalate privileges and access files outside of restricted
areas (CVE-2019-10216).
Also, the Mageia 7 update fixes a bounding box issue that affects
klatexformula (mga#24866).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | ghostscript | 0 (affected), 9.27-1.2.mga7 (unaffected), 0 (affected), 9.27-1.2.mga7 (unaffected) | — |
| Mageia | iw | 0 (affected), 5.4-1.mga7 (unaffected) | — |
| Mageia | ghostscript | 0 (affected), 9.26-1.5.mga6 (unaffected), 0 (affected), 9.26-1.5.mga6 (unaffected) | — |
Aliases
Transitive aliases
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.