Описание
Security update for ghostscript-library
This update for ghostscript-library fixes the following issues:
- CVE-2018-16511: A type confusion in 'ztype' could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact. (bsc#1107426)
- CVE-2018-16540: Attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact. (bsc#1107420)
- CVE-2018-16541: Attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter. (bsc#1107421)
- CVE-2018-16542: Attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter. (bsc#1107413)
- CVE-2018-16509: Incorrect 'restoration of privilege' checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the 'pipe' instruction. (bsc#1107410
- CVE-2018-16513: Attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact. (bsc#1107412)
- CVE-2018-15910: Attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code. (bsc#1106173)
- CVE-2017-9611: The Ins_MIRP function allowed remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document. (bsc#1050893)
Список пакетов
SUSE Linux Enterprise Point of Sale 11 SP3
SUSE Linux Enterprise Server 11 SP3-LTSS
SUSE Linux Enterprise Server 11 SP3-TERADATA
SUSE Linux Enterprise Server 11 SP4
SUSE Linux Enterprise Server for SAP Applications 11 SP4
SUSE Linux Enterprise Software Development Kit 11 SP4
Ссылки
- Link for SUSE-SU-2018:3330-1
- E-Mail link for SUSE-SU-2018:3330-1
- SUSE Security Ratings
- SUSE Bug 1050893
- SUSE Bug 1106173
- SUSE Bug 1107410
- SUSE Bug 1107412
- SUSE Bug 1107413
- SUSE Bug 1107420
- SUSE Bug 1107421
- SUSE Bug 1107426
- SUSE CVE CVE-2017-9611 page
- SUSE CVE CVE-2018-15910 page
- SUSE CVE CVE-2018-16509 page
- SUSE CVE CVE-2018-16511 page
- SUSE CVE CVE-2018-16513 page
- SUSE CVE CVE-2018-16540 page
- SUSE CVE CVE-2018-16541 page
- SUSE CVE CVE-2018-16542 page
Описание
The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.
Затронутые продукты
Ссылки
- CVE-2017-9611
- SUSE Bug 1050893
Описание
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.
Затронутые продукты
Ссылки
- CVE-2018-15910
- SUSE Bug 1105464
- SUSE Bug 1106173
Описание
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.
Затронутые продукты
Ссылки
- CVE-2018-16509
- SUSE Bug 1107410
- SUSE Bug 1108027
- SUSE Bug 1118318
Описание
An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.
Затронутые продукты
Ссылки
- CVE-2018-16511
- SUSE Bug 1107426
- SUSE Bug 1111479
- SUSE Bug 1112229
Описание
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.
Затронутые продукты
Ссылки
- CVE-2018-16513
- SUSE Bug 1107412
Описание
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.
Затронутые продукты
Ссылки
- CVE-2018-16540
- SUSE Bug 1107420
Описание
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.
Затронутые продукты
Ссылки
- CVE-2018-16541
- SUSE Bug 1107421
- SUSE Bug 1108027
- SUSE Bug 1109105
- SUSE Bug 1111479
- SUSE Bug 1111480
- SUSE Bug 1112229
- SUSE Bug 1117022
- SUSE Bug 1118455
Описание
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter.
Затронутые продукты
Ссылки
- CVE-2018-16542
- SUSE Bug 1107413