Ghostscript could be made to access arbitrary files if it opened a
specially crafted file.
- ghostscript: PostScript and PDF interpreter
Hiroki Matsukuma discovered that the PDF interpreter in Ghostscript
did not properly restrict privileged calls when ‘-dSAFER’
restrictions were in effect. If a user or automated system were
tricked into processing a specially crafted file, a remote attacker
could possibly use this issue to access arbitrary files.
(CVE-2019-14811, CVE-2019-14812, CVE-2019-14813, CVE-2019-14817)
The problem can be corrected by updating your system to the following