Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2018:1140-1

Опубликовано: 03 мая 2018
Источник: suse-cvrf

Описание

Security update for ghostscript-library

This update for ghostscript-library fixes several issues.

These security issues were fixed:

  • CVE-2017-7207: The mem_get_bits_rectangle function allowed remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PostScript document (bsc#1030263).
  • CVE-2016-9601: Prevent heap-buffer overflow by checking for an integer overflow in jbig2_image_new function (bsc#1018128).
  • CVE-2017-9612: The Ins_IP function in base/ttinterp.c allowed remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via a crafted document (bsc#1050891)
  • CVE-2017-9726: The Ins_MDRP function in base/ttinterp.c allowed remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document (bsc#1050889)
  • CVE-2017-9727: The gx_ttfReader__Read function in base/gxttfb.c allowed remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document (bsc#1050888)
  • CVE-2017-9739: The Ins_JMPR function in base/ttinterp.c allowed remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document (bsc#1050887)
  • CVE-2017-11714: psi/ztoken.c mishandled references to the scanner state structure, which allowed remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document, related to an out-of-bounds read in the igc_reloc_struct_ptr function in psi/igc.c (bsc#1051184)
  • CVE-2017-9835: The gs_alloc_ref_array function allowed remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document (bsc#1050879)
  • CVE-2016-10219: The intersect function in base/gxfill.c allowed remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file (bsc#1032138)
  • CVE-2017-9216: Prevent NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffman.c which allowed for DoS (bsc#1040643)

Список пакетов

SUSE Linux Enterprise Server 11 SP4
ghostscript-fonts-other-8.62-32.47.7.1
ghostscript-fonts-rus-8.62-32.47.7.1
ghostscript-fonts-std-8.62-32.47.7.1
ghostscript-library-8.62-32.47.7.1
ghostscript-omni-8.62-32.47.7.1
ghostscript-x11-8.62-32.47.7.1
libgimpprint-4.2.7-32.47.7.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
ghostscript-fonts-other-8.62-32.47.7.1
ghostscript-fonts-rus-8.62-32.47.7.1
ghostscript-fonts-std-8.62-32.47.7.1
ghostscript-library-8.62-32.47.7.1
ghostscript-omni-8.62-32.47.7.1
ghostscript-x11-8.62-32.47.7.1
libgimpprint-4.2.7-32.47.7.1
SUSE Linux Enterprise Software Development Kit 11 SP4
ghostscript-devel-8.62-32.47.7.1
ghostscript-ijs-devel-8.62-32.47.7.1
libgimpprint-devel-4.2.7-32.47.7.1

Описание

The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-other-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-rus-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-std-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-library-8.62-32.47.7.1

Ссылки

Описание

ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halftone segments in a JBIG2 image. A document (PostScript or PDF) with an embedded, specially crafted, jbig2 image could trigger a segmentation fault in ghostscript.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-other-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-rus-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-std-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-library-8.62-32.47.7.1

Ссылки

Описание

psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the scanner state structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document, related to an out-of-bounds read in the igc_reloc_struct_ptr function in psi/igc.c.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-other-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-rus-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-std-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-library-8.62-32.47.7.1

Ссылки

Описание

The mem_get_bits_rectangle function in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PostScript document.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-other-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-rus-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-std-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-library-8.62-32.47.7.1

Ссылки

Описание

libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffman.c. For example, the jbig2dec utility will crash (segmentation fault) when parsing an invalid file.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-other-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-rus-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-std-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-library-8.62-32.47.7.1

Ссылки

Описание

The Ins_IP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via a crafted document.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-other-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-rus-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-std-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-library-8.62-32.47.7.1

Ссылки

Описание

The Ins_MDRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-other-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-rus-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-std-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-library-8.62-32.47.7.1

Ссылки

Описание

The gx_ttfReader__Read function in base/gxttfb.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-other-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-rus-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-std-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-library-8.62-32.47.7.1

Ссылки

Описание

The Ins_JMPR function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-other-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-rus-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-std-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-library-8.62-32.47.7.1

Ссылки

Описание

The gs_alloc_ref_array function in psi/ialloc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document. This is related to a lack of an integer overflow check in base/gsalloc.c.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-other-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-rus-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-fonts-std-8.62-32.47.7.1
SUSE Linux Enterprise Server 11 SP4:ghostscript-library-8.62-32.47.7.1

Ссылки
Уязвимость SUSE-SU-2018:1140-1