Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:4140-1

Опубликовано: 15 дек. 2018
Источник: suse-cvrf

Описание

Security update for ghostscript

This update for ghostscript to version 9.26 fixes the following issues:

Security issues fixed:

  • CVE-2018-19475: Fixed bypass of an intended access restriction in psi/zdevice2.c (bsc#1117327)
  • CVE-2018-19476: Fixed bypass of an intended access restriction in psi/zicc.c (bsc#1117313)
  • CVE-2018-19477: Fixed bypass of an intended access restriction in psi/zfjbig2.c (bsc#1117274)
  • CVE-2018-19409: Check if another device is used correctly in LockSafetyParams (bsc#1117022)
  • CVE-2018-18284: Fixed potential sandbox escape through 1Policy operator (bsc#1112229)
  • CVE-2018-18073: Fixed leaks through operator in saved execution stacks (bsc#1111480)
  • CVE-2018-17961: Fixed a -dSAFER sandbox escape by bypassing executeonly (bsc#1111479)
  • CVE-2018-17183: Fixed a potential code injection by specially crafted PostScript files (bsc#1109105)

Version update to 9.26 (bsc#1117331):

This update was imported from the SUSE:SLE-12:Update update project.

Список пакетов

openSUSE Leap 42.3
ghostscript-9.26-14.12.1
ghostscript-devel-9.26-14.12.1
ghostscript-mini-9.26-14.12.1
ghostscript-mini-devel-9.26-14.12.1
ghostscript-x11-9.26-14.12.1
libspectre-0.2.7-17.4.2
libspectre-devel-0.2.7-17.4.2
libspectre1-0.2.7-17.4.2

Описание

Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code.


Затронутые продукты
openSUSE Leap 42.3:ghostscript-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-devel-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-devel-9.26-14.12.1

Ссылки

Описание

Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.


Затронутые продукты
openSUSE Leap 42.3:ghostscript-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-devel-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-devel-9.26-14.12.1

Ссылки

Описание

Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object.


Затронутые продукты
openSUSE Leap 42.3:ghostscript-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-devel-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-devel-9.26-14.12.1

Ссылки

Описание

Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.


Затронутые продукты
openSUSE Leap 42.3:ghostscript-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-devel-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-devel-9.26-14.12.1

Ссылки

Описание

An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.


Затронутые продукты
openSUSE Leap 42.3:ghostscript-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-devel-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-devel-9.26-14.12.1

Ссылки

Описание

psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.


Затронутые продукты
openSUSE Leap 42.3:ghostscript-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-devel-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-devel-9.26-14.12.1

Ссылки

Описание

psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.


Затронутые продукты
openSUSE Leap 42.3:ghostscript-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-devel-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-devel-9.26-14.12.1

Ссылки

Описание

psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.


Затронутые продукты
openSUSE Leap 42.3:ghostscript-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-devel-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-9.26-14.12.1
openSUSE Leap 42.3:ghostscript-mini-devel-9.26-14.12.1

Ссылки
Уязвимость openSUSE-SU-2018:4140-1