ALPINE-CVE-2019-3838

Source
https://security.alpinelinux.org/vuln/CVE-2019-3838
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2019-3838.json
JSON Data
https://api.test.osv.dev/v1/vulns/ALPINE-CVE-2019-3838
Upstream
Published
2019-03-25T19:29:01Z
Modified
2025-09-26T00:13:06.096178Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

References

Affected packages

Alpine:v3.10

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.11

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.12

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.13

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.14

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.15

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.16

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.17

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.18

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.19

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.20

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.21

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.22

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.6

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.7

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.8

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1

Alpine:v3.9

ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.26-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1