CVE-2019-6116 is a high-severity remote code execution vulnerability affecting Artifex Ghostscript through version 9.26, as well as various distributions like Canonical, Debian, Fedora, openSUSE, and Red Hat. The flaw allows ephemeral or transient procedures to access system operators, enabling an attacker to execute arbitrary code. With a CVSS score of 7.8 (High) and a FAUCET Risk Score of 98/100, this vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L) and can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-46242) confirms the existence of public exploit code, and it has garnered significant community discussion and media coverage, indicating active awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.26CPE matchmatch criteria | cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:* | ||
28CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.