CVE-2019-14813: Artifex Ghostscript

Critical severity, CVSS 9.8. EPSS: 11.4% chance of exploitation in the next 30 days.

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

Affected products

  • Artifex Ghostscript: from 9.00, up to and including 9.50
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 29 only; version 30 only; version 31 only
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.7 only
  • Red Hat Enterprise Linux Server Eus: version 7.7 only
  • Red Hat Enterprise Linux Server Tus: version 7.7 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Red Hat Openshift Container Platform: version 3.11 only; version 4.1 only

Published 2019-09-06. Last modified 2026-06-17.