Описание
Security update for ghostscript
This update for ghostscript to version 9.25 fixes the following issues:
These security issues were fixed:
- CVE-2018-17183: Remote attackers were be able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code (bsc#1109105)
- CVE-2018-15909: Prevent type confusion using the .shfill operator that could have been used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code (bsc#1106172).
- CVE-2018-15908: Prevent attackers that are able to supply malicious PostScript files to bypass .tempfile restrictions and write files (bsc#1106171).
- CVE-2018-15910: Prevent a type confusion in the LockDistillerParams parameter that could have been used to crash the interpreter or execute code (bsc#1106173).
- CVE-2018-15911: Prevent use uninitialized memory access in the aesdecode operator that could have been used to crash the interpreter or potentially execute code (bsc#1106195).
- CVE-2018-16513: Prevent a type confusion in the setcolor function that could have been used to crash the interpreter or possibly have unspecified other impact (bsc#1107412).
- CVE-2018-16509: Incorrect 'restoration of privilege' checking during handling of /invalidaccess exceptions could be have been used by attackers able to supply crafted PostScript to execute code using the 'pipe' instruction (bsc#1107410).
- CVE-2018-16510: Incorrect exec stack handling in the 'CS' and 'SC' PDF primitives could have been used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact (bsc#1107411).
- CVE-2018-16542: Prevent attackers able to supply crafted PostScript files from using insufficient interpreter stack-size checking during error handling to crash the interpreter (bsc#1107413).
- CVE-2018-16541: Prevent attackers able to supply crafted PostScript files from using incorrect free logic in pagedevice replacement to crash the interpreter (bsc#1107421).
- CVE-2018-16540: Prevent use-after-free in copydevice handling that could have been used to crash the interpreter or possibly have unspecified other impact (bsc#1107420).
- CVE-2018-16539: Prevent attackers able to supply crafted PostScript files from using incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable (bsc#1107422).
- CVE-2018-16543: gssetresolution and gsgetresolution allowed attackers to have an unspecified impact (bsc#1107423).
- CVE-2018-16511: A type confusion in 'ztype' could have been used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact (bsc#1107426).
- CVE-2018-16585: The .setdistillerkeys PostScript command was accepted even though it is not intended for use during document processing (e.g., after the startup phase). This lead to memory corruption, allowing remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact (bsc#1107581).
- CVE-2018-16802: Incorrect 'restoration of privilege' checking when running out of stack during exception handling could have been used by attackers able to supply crafted PostScript to execute code using the 'pipe' instruction. This is due to an incomplete fix for CVE-2018-16509 (bsc#1108027).
These non-security issues were fixed:
- Fixes problems with argument handling, some unintended results of the security fixes to the SAFER file access restrictions (specifically accessing ICC profile files).
- Avoid that ps2epsi fails with 'Error: /undefined in --setpagedevice--'
For additional changes please check http://www.ghostscript.com/doc/9.25/News.htm
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15
SUSE Linux Enterprise Module for Desktop Applications 15
Ссылки
- Link for SUSE-SU-2018:2976-1
- E-Mail link for SUSE-SU-2018:2976-1
- SUSE Security Ratings
- SUSE Bug 1106171
- SUSE Bug 1106172
- SUSE Bug 1106173
- SUSE Bug 1106195
- SUSE Bug 1107410
- SUSE Bug 1107411
- SUSE Bug 1107412
- SUSE Bug 1107413
- SUSE Bug 1107420
- SUSE Bug 1107421
- SUSE Bug 1107422
- SUSE Bug 1107423
- SUSE Bug 1107426
- SUSE Bug 1107581
- SUSE Bug 1108027
- SUSE Bug 1109105
- SUSE CVE CVE-2018-15908 page
Описание
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
Затронутые продукты
Ссылки
- CVE-2018-15908
- SUSE Bug 1105464
- SUSE Bug 1106171
Описание
In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
Затронутые продукты
Ссылки
- CVE-2018-15909
- SUSE Bug 1105464
- SUSE Bug 1106172
Описание
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.
Затронутые продукты
Ссылки
- CVE-2018-15910
- SUSE Bug 1105464
- SUSE Bug 1106173
Описание
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
Затронутые продукты
Ссылки
- CVE-2018-15911
- SUSE Bug 1105464
- SUSE Bug 1106195
- SUSE Bug 1108027
- SUSE Bug 1109105
- SUSE Bug 1111479
- SUSE Bug 1111480
- SUSE Bug 1112229
- SUSE Bug 1117022
- SUSE Bug 1118455
Описание
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.
Затронутые продукты
Ссылки
- CVE-2018-16509
- SUSE Bug 1107410
- SUSE Bug 1108027
- SUSE Bug 1118318
Описание
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact.
Затронутые продукты
Ссылки
- CVE-2018-16510
- SUSE Bug 1107411
Описание
An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.
Затронутые продукты
Ссылки
- CVE-2018-16511
- SUSE Bug 1107426
- SUSE Bug 1111479
- SUSE Bug 1112229
Описание
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.
Затронутые продукты
Ссылки
- CVE-2018-16513
- SUSE Bug 1107412
Описание
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.
Затронутые продукты
Ссылки
- CVE-2018-16539
- SUSE Bug 1107422
Описание
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.
Затронутые продукты
Ссылки
- CVE-2018-16540
- SUSE Bug 1107420
Описание
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.
Затронутые продукты
Ссылки
- CVE-2018-16541
- SUSE Bug 1107421
- SUSE Bug 1108027
- SUSE Bug 1109105
- SUSE Bug 1111479
- SUSE Bug 1111480
- SUSE Bug 1112229
- SUSE Bug 1117022
- SUSE Bug 1118455
Описание
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter.
Затронутые продукты
Ссылки
- CVE-2018-16542
- SUSE Bug 1107413
Описание
In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.
Затронутые продукты
Ссылки
- CVE-2018-16543
- SUSE Bug 1107423
Описание
An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even though it is not intended for use during document processing (e.g., after the startup phase). This leads to memory corruption, allowing remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact. Note: A reputable source believes that the CVE is potentially a duplicate of CVE-2018-15910 as explained in Red Hat bugzilla (https://bugzilla.redhat.com/show_bug.cgi?id=1626193)
Затронутые продукты
Ссылки
- CVE-2018-16585
- SUSE Bug 1107581
Описание
An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to an incomplete fix for CVE-2018-16509.
Затронутые продукты
Ссылки
- CVE-2018-16802
- SUSE Bug 1107410
- SUSE Bug 1108027
- SUSE Bug 1109105
- SUSE Bug 1111479
- SUSE Bug 1111480
- SUSE Bug 1112229
- SUSE Bug 1117022
- SUSE Bug 1117327
- SUSE Bug 1118455
Описание
Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code.
Затронутые продукты
Ссылки
- CVE-2018-17183
- SUSE Bug 1108027
- SUSE Bug 1109105
- SUSE Bug 1111479
- SUSE Bug 1111480
- SUSE Bug 1112229
- SUSE Bug 1117022
- SUSE Bug 1117331
- SUSE Bug 1118455