VYPR
High severity7.8NVD Advisory· Published Nov 27, 2019· Updated Jun 17, 2026

CVE-2019-14812

CVE-2019-14812

Description

A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass -dSAFER restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

31

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.