CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.8. See the original NVD description below for full technical details.
CVE
CVE-2019-10216
Severity
HIGH
CVSS
7.8
EPSS
2.30%
Original NVD Description
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.
Related CVEs
Other vulnerabilities affecting the same vendor(s)