CVE-2019-10216: Artifex Ghostscript
High severity, CVSS 7.8. EPSS: 2.3% chance of exploitation in the next 30 days.
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.
Affected products
- Artifex Ghostscript: before 9.50 (fixed in 9.50)
- Red Hat 3scale API Management: version 2.6 only
- Red Hat Enterprise Linux: version 5.0 only; version 6.0 only; version 8.0 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.7 only
- Red Hat Enterprise Linux Server Eus: version 7.7 only
- Red Hat Enterprise Linux Server Tus: version 7.7 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2019-11-27. Last modified 2026-06-17.