Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 40: FEDORA-2024-939eac36ae Critical: Ghostscript Code Execution

fedora
Calendar Grey June 18, 2024
Dist Fedora Esm H88
A security patch for CVE-2024-33871 in Ghostscript on Fedora 40 has been released, focusing on key enhancements and installation guidance to secure systems
Security fix for CVE-2024-33871

Summary

This package provides useful conversion utilities based on Ghostscript software,

for converting PS, PDF and other document formats between each other.

Ghostscript is a suite of software providing an interpreter for Adobe Systems'

PostScript (PS) and Portable Document Format (PDF) page description languages.

Its primary purpose includes displaying (rasterization & rendering) and printing

of document pages, as well as conversions between different document formats.

Update Information:

Security fix for CVE-2024-33871

Change Log

* Thu May 30 2024 Zdenek Dohnal - 10.02.1-9 - 2283509 - CVE-2024-33871 ghostscript: OPVP device arbitrary code execution via custom Driver library

References


[ 1 ] Bug #2283508 - CVE-2024-33871 ghostscript: OPVP device arbitrary code execution via custom Driver library https://bugzilla.redhat.com/show_bug.cgi?id=2283508

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-939eac36ae' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ghostscript
Product: Fedora 40
Version: 10.02.1
Release: 9.fc40
Summary: Interpreter for PostScript language & PDF

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here