Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20592-1

Опубликовано: 21 апр. 2026
Источник: suse-cvrf

Описание

Security update for ghostscript

This update for ghostscript fixes the following issues:

Update to version 10.06.0.

Security issues fixed:

  • CVE-2025-59800: an integer overflow can lead to a heap-based buffer overflow in ocr_line8 (bsc#1250355).
  • CVE-2025-59799: a large size value can cause a stack-based buffer overflow in pdfmark_coerce_dest (bsc#1250354).
  • CVE-2025-59798: stack-based buffer overflow in pdf_write_cmap can lead to a denial-of-service (bsc#1250353).
  • CVE-2025-48708: lacks of argument sanitization may lead to password disclosure (bsc#1243701).
  • CVE-2025-46646: mishandling of overlong utf-8 encoding in artifex ghostscript's decode_utf8 function (bsc#1257699).

Other updates and bugfixes:

  • switch over to libalternatives for ghostscript to provide a gs variant (bsc#1245896)

  • Version upgrade to 10.06.0:

    • removes the non-standard operator "selectdevice" (cf. the entry below dated Tue Apr 1 09:56:06 UTC 2025)
  • Version upgrade to 10.05.1:

    • an overflow issue in Freetype on platforms where long is a 4 byte (rather than 8 byte) type (Microsoft Windows, for example) causing corrupted glyph rendering at higher resolutions
    • an issue with embedded files, affecting Zugferd format PDF creation.
    • broken logic in PDF Optional Content processing
    • potential slow down due to searching for identifiable font files
    • a small number of extreme edge case segmentation faults.

Список пакетов

openSUSE Leap 16.0
ghostscript-10.06.0-160000.1.1
ghostscript-devel-10.06.0-160000.1.1
ghostscript-x11-10.06.0-160000.1.1

Описание

In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.


Затронутые продукты
openSUSE Leap 16.0:ghostscript-10.06.0-160000.1.1
openSUSE Leap 16.0:ghostscript-devel-10.06.0-160000.1.1
openSUSE Leap 16.0:ghostscript-x11-10.06.0-160000.1.1

Ссылки

Описание

gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.


Затронутые продукты
openSUSE Leap 16.0:ghostscript-10.06.0-160000.1.1
openSUSE Leap 16.0:ghostscript-devel-10.06.0-160000.1.1
openSUSE Leap 16.0:ghostscript-x11-10.06.0-160000.1.1

Ссылки

Описание

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.


Затронутые продукты
openSUSE Leap 16.0:ghostscript-10.06.0-160000.1.1
openSUSE Leap 16.0:ghostscript-devel-10.06.0-160000.1.1
openSUSE Leap 16.0:ghostscript-x11-10.06.0-160000.1.1

Ссылки

Описание

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value.


Затронутые продукты
openSUSE Leap 16.0:ghostscript-10.06.0-160000.1.1
openSUSE Leap 16.0:ghostscript-devel-10.06.0-160000.1.1
openSUSE Leap 16.0:ghostscript-x11-10.06.0-160000.1.1

Ссылки

Описание

In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.


Затронутые продукты
openSUSE Leap 16.0:ghostscript-10.06.0-160000.1.1
openSUSE Leap 16.0:ghostscript-devel-10.06.0-160000.1.1
openSUSE Leap 16.0:ghostscript-x11-10.06.0-160000.1.1

Ссылки

Описание

In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked.


Затронутые продукты
openSUSE Leap 16.0:ghostscript-10.06.0-160000.1.1
openSUSE Leap 16.0:ghostscript-devel-10.06.0-160000.1.1
openSUSE Leap 16.0:ghostscript-x11-10.06.0-160000.1.1

Ссылки