MGASA-2019-0271 - Updated ghostscript packages fix security vulnerabilities

Publication date: 12 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0271.html
Type: security
Affected Mageia releases: 6, 7
CVE: CVE-2019-14811,
     CVE-2019-14812,
     CVE-2019-14813

The updated packages fix security vulnerabilities:

Safer Mode Bypass by .forceput Exposure in .pdf_hook_DSC_Creator.
(CVE-2019-14811)

Safer Mode Bypass by .forceput Exposure in setuserparams. (CVE-2019-14812)

Safer Mode Bypass by .forceput Exposure in setsystemparams. (CVE-2019-14813)

Safer Mode Bypass by .forceput Exposure in .pdfexectoken and other
procedures. (CVE-2019-14817)

References:
- https://bugs.mageia.org/show_bug.cgi?id=25379
- https://www.openwall.com/lists/oss-security/2019/08/28/2
- https://access.redhat.com/errata/RHSA-2019:2586
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14811
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14812
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14813

SRPMS:
- 7/core/ghostscript-9.27-1.3.mga7
- 6/core/ghostscript-9.26-1.6.mga6

Mageia 2019-0271: ghostscript security update

The updated packages fix security vulnerabilities: Safer Mode Bypass by .forceput Exposure in .pdf_hook_DSC_Creator

Summary

The updated packages fix security vulnerabilities:
Safer Mode Bypass by .forceput Exposure in .pdf_hook_DSC_Creator. (CVE-2019-14811)
Safer Mode Bypass by .forceput Exposure in setuserparams. (CVE-2019-14812)
Safer Mode Bypass by .forceput Exposure in setsystemparams. (CVE-2019-14813)
Safer Mode Bypass by .forceput Exposure in .pdfexectoken and other procedures. (CVE-2019-14817)

References

- https://bugs.mageia.org/show_bug.cgi?id=25379

- https://www.openwall.com/lists/oss-security/2019/08/28/2

- https://access.redhat.com/errata/RHSA-2019:2586

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14811

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14812

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14813

Resolution

MGASA-2019-0271 - Updated ghostscript packages fix security vulnerabilities

SRPMS

- 7/core/ghostscript-9.27-1.3.mga7

- 6/core/ghostscript-9.26-1.6.mga6

Severity
Publication date: 12 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0271.html
Type: security
CVE: CVE-2019-14811, CVE-2019-14812, CVE-2019-14813

Related News