Описание
Security update for ghostscript-library
This update for ghostscript-library fixes the following issues:
-
Multiple security vulnerabilities have been discovered where ghostscript's '-dsafer' flag did not provide sufficient protection against unintended access to the file system. Thus, a machine that would process a specially crafted Postscript file would potentially leak sensitive information to an attacker. (CVE-2013-5653, CVE-2016-7977, bsc#1001951)
-
Insufficient validation of the type of input in .initialize_dsc_parser used to allow remote code execution. (CVE-2016-7979, bsc#1001951)
-
An integer overflow in the gs_heap_alloc_bytes function used to allow remote attackers to cause a denial of service (crash) via specially crafted Postscript files. (CVE-2015-3228, boo#939342)
Список пакетов
SUSE Linux Enterprise Point of Sale 11 SP3
SUSE Linux Enterprise Server 11 SP2-LTSS
SUSE Linux Enterprise Server 11 SP3-LTSS
SUSE Linux Enterprise Server 11 SP3-TERADATA
SUSE Linux Enterprise Server 11 SP4
SUSE Linux Enterprise Server for SAP Applications 11 SP4
SUSE Linux Enterprise Software Development Kit 11 SP4
SUSE Manager 2.1
SUSE Manager Proxy 2.1
SUSE OpenStack Cloud 5
Ссылки
- Link for SUSE-SU-2016:2493-1
- E-Mail link for SUSE-SU-2016:2493-1
- SUSE Security Ratings
- SUSE Bug 1001951
- SUSE Bug 939342
- SUSE CVE CVE-2013-5653 page
- SUSE CVE CVE-2015-3228 page
- SUSE CVE CVE-2016-7977 page
- SUSE CVE CVE-2016-7979 page
Описание
The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.
Затронутые продукты
Ссылки
- CVE-2013-5653
- SUSE Bug 1001951
- SUSE Bug 1004237
- SUSE Bug 1007816
- SUSE Bug 1036453
Описание
Integer overflow in the gs_heap_alloc_bytes function in base/gsmalloc.c in Ghostscript 9.15 and earlier allows remote attackers to cause a denial of service (crash) via a crafted Postscript (ps) file, as demonstrated by using the ps2pdf command, which triggers an out-of-bounds read or write.
Затронутые продукты
Ссылки
- CVE-2015-3228
- SUSE Bug 939342
Описание
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.
Затронутые продукты
Ссылки
- CVE-2016-7977
- SUSE Bug 1001951
- SUSE Bug 1004237
- SUSE Bug 1095610
Описание
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.
Затронутые продукты
Ссылки
- CVE-2016-7979
- SUSE Bug 1001951
- SUSE Bug 1004237