[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2016:2493-1 -- SLES ghostscript-library, ghostscript-fonts-other, ghostscript-fonts-rus, ghostscript-fonts-std, ghostscript-omni, ghostscript-x11, libgimpprint

ID: oval:org.secpod.oval:def:89045353Date: (C)2021-08-03   (M)2021-11-15
Class: PATCHFamily: unix




This update for ghostscript-library fixes the following issues: - Multiple security vulnerabilities have been discovered where ghostscript"s -dsafer flag did not provide sufficient protection against unintended access to the file system. Thus, a machine that would process a specially crafted Postscript file would potentially leak sensitive information to an attacker. - Insufficient validation of the type of input in .initialize_dsc_parser used to allow remote code execution. - An integer overflow in the gs_heap_alloc_bytes function used to allow remote attackers to cause a denial of service via specially crafted Postscript files

Platform:
SUSE Linux Enterprise Server 11 SP4
Product:
ghostscript-library
ghostscript-fonts-other
ghostscript-fonts-rus
ghostscript-fonts-std
ghostscript-omni
ghostscript-x11
libgimpprint
Reference:
SUSE-SU-2016:2493-1
CVE-2013-5653
CVE-2015-3228
CVE-2016-7977
CVE-2016-7979
CVE    4
CVE-2016-7979
CVE-2016-7977
CVE-2013-5653
CVE-2015-3228
...
CPE    2
cpe:/a:libgimpprint:libgimpprint
cpe:/o:suse:suse_linux_enterprise_server:11:sp4

© SecPod Technologies