[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2018:3330-1 -- SLES ghostscript

ID: oval:org.secpod.oval:def:89002407Date: (C)2021-02-26   (M)2024-04-17
Class: PATCHFamily: unix




This update for ghostscript-library fixes the following issues: - CVE-2018-16511: A type confusion in quot;ztypequot; could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact. - CVE-2018-16540: Attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact. - CVE-2018-16541: Attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter. - CVE-2018-16542: Attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter. - CVE-2018-16509: Incorrect quot;restoration of privilegequot; checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the quot;pipequot; instruction

Platform:
SUSE Linux Enterprise Server 11 SP4
Product:
ghostscript
Reference:
SUSE-SU-2018:3330-1
CVE-2017-9611
CVE-2018-15910
CVE-2018-16509
CVE-2018-16511
CVE-2018-16513
CVE-2018-16540
CVE-2018-16541
CVE-2018-16542
CVE    8
CVE-2017-9611
CVE-2018-16540
CVE-2018-16509
CVE-2018-15910
...
CPE    2
cpe:/a:ghostscript:ghostscript
cpe:/o:suse:suse_linux_enterprise_server:11:sp4

© SecPod Technologies