Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian 8: DLA-1992-1 Critical Ghostscript Sandbox Bypass

debian lts
Calendar Grey November 14, 2019
Dist Debian Esm H88
Significant Ghostscript vulnerability alert highlights potential file exposure implications through .charkeys function for Debian 8 installations.
Manfred Paul and Lukas Schauer reported that the .charkeys procedure in Ghostscript, the GPL PostScript/PDF interpreter, does not properly restrict privileged calls, which could re...

Summary

For Debian 8 "Jessie", this problem has been fixed in version
9.26a~dfsg-0+deb8u6.

We recommend that you upgrade your ghostscript packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: ghostscript
Version: 9.26a~dfsg-0+deb8u6
CVE ID: CVE-2019-14869

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here