Описание
Security update for ghostscript
This update for ghostscript to version 9.52 fixes the following issues:
- CVE-2020-12268: Fixed a heap-based buffer overflow in jbig2_image_compose (bsc#1170603).
Список пакетов
SUSE Linux Enterprise High Performance Computing 15-ESPOS
ghostscript-9.52-3.27.2
ghostscript-devel-9.52-3.27.2
ghostscript-x11-9.52-3.27.2
libspectre1-0.2.8-3.10.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
ghostscript-9.52-3.27.2
ghostscript-devel-9.52-3.27.2
ghostscript-x11-9.52-3.27.2
libspectre1-0.2.8-3.10.1
SUSE Linux Enterprise Module for Basesystem 15 SP1
ghostscript-9.52-3.27.2
ghostscript-devel-9.52-3.27.2
ghostscript-x11-9.52-3.27.2
SUSE Linux Enterprise Module for Desktop Applications 15 SP1
libspectre-devel-0.2.8-3.10.1
libspectre1-0.2.8-3.10.1
SUSE Linux Enterprise Server 15-LTSS
ghostscript-9.52-3.27.2
ghostscript-devel-9.52-3.27.2
ghostscript-x11-9.52-3.27.2
libspectre1-0.2.8-3.10.1
SUSE Linux Enterprise Server for SAP Applications 15
ghostscript-9.52-3.27.2
ghostscript-devel-9.52-3.27.2
ghostscript-x11-9.52-3.27.2
libspectre1-0.2.8-3.10.1
Ссылки
- Link for SUSE-SU-2020:1220-1
- E-Mail link for SUSE-SU-2020:1220-1
- SUSE Security Ratings
- SUSE Bug 1170603
- SUSE CVE CVE-2020-12268 page
Описание
jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:ghostscript-9.52-3.27.2
SUSE Linux Enterprise High Performance Computing 15-ESPOS:ghostscript-devel-9.52-3.27.2
SUSE Linux Enterprise High Performance Computing 15-ESPOS:ghostscript-x11-9.52-3.27.2
SUSE Linux Enterprise High Performance Computing 15-ESPOS:libspectre1-0.2.8-3.10.1
Ссылки
- CVE-2020-12268
- SUSE Bug 1170603