Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 27 2018-f1b1ed38b3 Critical Ghostscript Memory Corruption

fedora
Calendar Grey September 17, 2018
Dist Fedora Esm H88
The latest Debian patch resolves significant vulnerabilities in Ghostscript that impact PostScript and PDF processing.
Security update for `CVE-2018-16543` and `CVE-2018-16510`, which were recently discovered.

Summary

Ghostscript is a set of software that provides a PostScript

interpreter, a set of C procedures (the Ghostscript library, which

implements the graphics capabilities in the PostScript language) and

an interpreter for Portable Document Format (PDF) files. Ghostscript

translates PostScript code into many common, bitmapped formats, like

those understood by your printer or screen. Ghostscript is normally

used to display PostScript files and to print PostScript files to

non-PostScript printers.

If you need to display PostScript files or print them to

non-PostScript printers, you should install ghostscript. If you

install ghostscript, you also need to install the urw-base35-fonts

package.

Security update for `CVE-2018-16543` and `CVE-2018-16510`, which were recently

discovered.

* Thu Sep 6 2018 David Kaspar [Dee'Kej] - 9.22-6

- Fix for CVE-2018-16510 added (bug #1625837)

- Fix for CVE-2018-16543 added (bug #1625852)

* Wed Aug 29 2018 David Kaspar [Dee'Kej] - 9.22-5

- ghostscript-9.22-fixes-for-set-of-CVEs-reported-by-Google.patch added

- Fix for CVE-2018-10194 correctly applied

* Mon Apr 23 2018 David Kaspar [Dee'Kej] - 9.22-4

- Fix for CVE-2018-10194 added (bug #1569821)

* Mon Dec 4 2017 David Kaspar [Dee'Kej] - 9.22-2

- Fontmap.GS lookup path for Helvetica-Narrow-Bold-Oblique font fixed (bug #1517518)

* Wed Nov 29 2017 Tom Callaway - 9.22-2

- apply post 9.22 upstream commit to restore flushpage operator (xdvi needs it)

[ 1 ] Bug #1625837 - CVE-2018-16510 ghostscript: Incorrect exec stack handling in the "CS" and "SC" PDF primitives (699671) [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1625837

[ 2 ] Bug #1625852 - CVE-2018-16543 ghostscript: gssetresolution and gsgetresolution memory corruption (699670) [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1625852

su -c 'dnf upgrade --advisory FEDORA-2018-f1b1ed38b3' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 9.22
Release: 6.fc27
Summary: A PostScript interpreter and renderer

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here