This update for ghostscript to version 9.25 fixes the following issues:
These security issues were fixed:
- CVE-2018-17183: Remote attackers were be able to supply crafted
PostScript to potentially overwrite or replace error handlers to inject
code (bsc#1109105)
- CVE-2018-15909: Prevent type confusion using the .shfill operator that
could have been used by attackers able to supply crafted PostScript
files to crash the interpreter or potentially execute code (bsc#1106172).
- CVE-2018-15908: Prevent attackers that are able to supply malicious
PostScript files to bypass .tempfile restrictions and write files
(bsc#1106171).
- CVE-2018-15910: Prevent a type confusion in the LockDistillerParams
parameter that could have been used to crash the interpreter or execute
code (bsc#1106173).
- CVE-2018-15911: Prevent use uninitialized memory access in the aesdecode
operator that could have been used to crash the interpreter or
...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2018-1122=1
- openSUSE Leap 42.3 (i586 x86_64):
ghostscript-9.25-14.9.1
ghostscript-debuginfo-9.25-14.9.1
ghostscript-debugsource-9.25-14.9.1
ghostscript-devel-9.25-14.9.1
ghostscript-mini-9.25-14.9.1
ghostscript-mini-debuginfo-9.25-14.9.1
ghostscript-mini-debugsource-9.25-14.9.1
ghostscript-mini-devel-9.25-14.9.1
ghostscript-x11-9.25-14.9.1
ghostscript-x11-debuginfo-9.25-14.9.1
https://www.suse.com/security/cve/CVE-2018-15908.html
https://www.suse.com/security/cve/CVE-2018-15909.html
https://www.suse.com/security/cve/CVE-2018-15910.html
https://www.suse.com/security/cve/CVE-2018-15911.html
https://www.suse.com/security/cve/CVE-2018-16509.html
https://www.suse.com/security/cve/CVE-2018-16510.html
https://www.suse.com/security/cve/CVE-2018-16511.html
https://www.suse.com/security/cve/CVE-2018-16513.html
https://www.suse.com/security/cve/CVE-2018-16539.html
https://www.suse.com/security/cve/CVE-2018-16540.html
https://www.suse.com/security/cve/CVE-2018-16541.html
https://www.suse.com/security/cve/CVE-2018-16542.html
https://www.suse.com/security/cve/CVE-2018-16543.html
https://www.suse.com/security/cve/CVE-2018-16585.html
https://www.suse.com/security/cve/CVE-2018-16802.html
https://www.suse.com/security/cve/CVE-2018-17183.html
https://bugzilla.suse.com/1106171
https://bugzilla.suse.com/1106172
https://bugzilla.suse.com/1106173
https://bugzilla.suse.com/1106195
https://bugzilla.sus...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.