Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2018-3761

Опубликовано: 03 дек. 2018
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2018-3761: ghostscript security and bug fix update (IMPORTANT)

[9.07-31.el7_6.3]

  • Resolves: #1654290 ghostscript update breaks xdvi (gs: Error: /undefined in flushpage)

[9.07-31.el7_6.2]

  • Resolves: #1652901 - CVE-2018-16863 ghostscript: incomplete fix for CVE-2018-16509

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

ghostscript

9.07-31.el7_6.3

ghostscript-cups

9.07-31.el7_6.3

ghostscript-devel

9.07-31.el7_6.3

ghostscript-doc

9.07-31.el7_6.3

ghostscript-gtk

9.07-31.el7_6.3

Oracle Linux x86_64

ghostscript

9.07-31.el7_6.3

ghostscript-cups

9.07-31.el7_6.3

ghostscript-devel

9.07-31.el7_6.3

ghostscript-doc

9.07-31.el7_6.3

ghostscript-gtk

9.07-31.el7_6.3

Связанные CVE

Связанные уязвимости

CVSS3: 7.3
ubuntu
почти 7 лет назад

It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat Enterprise Linux 7.

CVSS3: 7.3
redhat
почти 7 лет назад

It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat Enterprise Linux 7.

CVSS3: 7.3
nvd
почти 7 лет назад

It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat Enterprise Linux 7.

CVSS3: 7.3
debian
почти 7 лет назад

It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An ...

CVSS3: 7.8
github
больше 3 лет назад

It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat Enterprise Linux 7.