Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 40: FEDORA-2024-f433c5c4da Moderate: Ghostscript Security Fix

fedora
Calendar Grey July 2, 2024
Dist Fedora Esm H88
Fedora bolsters its system defense with Ghostscript security patches for CVE-2024-33870 and CVE-2024-29510.
Security fixes for CVE-2024-33870, CVE-2024-29510

Summary

This package provides useful conversion utilities based on Ghostscript software,

for converting PS, PDF and other document formats between each other.

Ghostscript is a suite of software providing an interpreter for Adobe Systems'

PostScript (PS) and Portable Document Format (PDF) page description languages.

Its primary purpose includes displaying (rasterization & rendering) and printing

of document pages, as well as conversions between different document formats.

Update Information:

Security fixes for CVE-2024-33870, CVE-2024-29510

Change Log

* Thu Jun 27 2024 Zdenek Dohnal - 10.02.1-10 - 2293951 - CVE-2024-29510 ghostscript: format string injection leads to shell command execution (SAFER bypass) - 2293960 - CVE-2024-33870 ghostscript: path traversal to arbitrary files if the current directory is in the permitted paths

References


[ 1 ] Bug #2293950 - CVE-2024-29510 ghostscript: format string injection leads to shell command execution (SAFER bypass) https://bugzilla.redhat.com/show_bug.cgi?id=2293950 [ 2 ] Bug #2293959 - CVE-2024-33870 ghostscript: path traversal to arbitrary files if the current directory is in the permitted paths https://bugzilla.redhat.com/show_bug.cgi?id=2293959

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-f433c5c4da' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Name: ghostscript
Product: Fedora 40
Version: 10.02.1
Release: 10.fc40
Summary: Interpreter for PostScript language & PDF

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here