Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Fedora 37: FEDORA-2023-83c805b441 moderate: ghostscript command injection

fedora
Calendar Grey July 23, 2023
Dist Fedora Esm H88
The security update addressing the Ghostscript vulnerability CVE-2023-36664 for Fedora 37 includes essential patches and enhancements to safeguard systems against potential threats.
fix for CVE-2023-36664 (rhbz#2217805)

Summary

This package provides useful conversion utilities based on Ghostscript software,

for converting PS, PDF and other document formats between each other.

Ghostscript is a suite of software providing an interpreter for Adobe Systems'

PostScript (PS) and Portable Document Format (PDF) page description languages.

Its primary purpose includes displaying (rasterization & rendering) and printing

of document pages, as well as conversions between different document formats.

Update Information:

fix for CVE-2023-36664 (rhbz#2217805)

Change Log

* Fri Jul 14 2023 Michael J Gruber - 9.56.1-8 - fix for CVE-2023-36664 (rhbz#2217805)

References


[ 1 ] Bug #2217805 - CVE-2023-36664 ghostscript: vulnerable to OS command injection due to mishandles permission validation for pipe devices [fedora-37] https://bugzilla.redhat.com/show_bug.cgi?id=2217805

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-83c805b441' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Name: ghostscript
Product: Fedora 37
Version: 9.56.1
Release: 8.fc37
Summary: Interpreter for PostScript language & PDF

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here