Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia 6 MGASA-2018-0408 Moderate: Ghostscript Escape Sandbox

mageia
Calendar Grey October 19, 2018
Dist Mageia Esm H88
Revamped ghostscript updates rectify vulnerabilities within Mageia 6, boosting package reliability and overall system protection.
Updated ghostscript packages fix many bugs and security vulnerabilities: Bypassing executeonly to escape -dSAFER sandbox

Summary

Updated ghostscript packages fix many bugs and security vulnerabilities:
Bypassing executeonly to escape -dSAFER sandbox. (CVE-2018-17961)
Saved execution stacks can leak operator arrays. (CVE-2018-18073)
1Policy operator gives access to .forceput. (CVE-2018-18284)

References

- https://bugs.mageia.org/show_bug.cgi?id=23659

- https://www.openwall.com/lists/oss-security/2018/10/09/4

- https://www.openwall.com/lists/oss-security/2018/10/11/3

- https://www.openwall.com/lists/oss-security/2018/10/10/12

- https://www.openwall.com/lists/oss-security/2018/10/16/2

- https://www.cve.org/CVERecord?id=CVE-2018-17961

- https://www.cve.org/CVERecord?id=CVE-2018-18073

- https://www.cve.org/CVERecord?id=CVE-2018-18284

Resolution

SRPMS

- 6/core/ghostscript-9.25-1.2.mga6

Publication date: 19 Oct 2018
URL: https://advisories.mageia.org/MGASA-2018-0408.html
Type: security
CVE: CVE-2018-17961, CVE-2018-18073, CVE-2018-18284

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here