A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
https://www.debian.org/security/2019/dsa-4518
https://security.gentoo.org/glsa/202004-03
https://seclists.org/bugtraq/2019/Sep/15
https://lists.debian.org/debian-lts-announce/2019/09/msg00007.html
https://access.redhat.com/errata/RHSA-2019:2594
https://access.redhat.com/errata/RHBA-2019:2824