For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The Ghostscript suite contains utilities for rendering PostScript and PDF
documents. Ghostscript translates PostScript code to common bitmap formats
so that the code can be displayed or printed.
Security Fix(es):
* ghostscript: superexec operator is available (700585) (CVE-2019-3835)
* ghostscript: forceput in DefineResource is still accessible (700576)
(CVE-2019-3838)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Bug Fix(es):
* ghostscript: Regression: double comment chars '%%' in gs_init.ps leading
to missing metadata (BZ#1673915)
https://access.redhat.com/security/cve/CVE-2019-3835 https://access.redhat.com/security/cve/CVE-2019-3838 https://access.redhat.com/security/updates/classification/#important
Red Hat Enterprise Linux Client (v. 7):
Source:
ghostscript-9.07-31.el7_6.10.src.rpm
x86_64:
ghostscript-9.07-31.el7_6.10.i686.rpm
ghostscript-9.07-31.el7_6.10.x86_64.rpm
ghostscript-cups-9.07-31.el7_6.10.x86_64.rpm
ghostscript-debuginfo-9.07-31.el7_6.10.i686.rpm
ghostscript-debuginfo-9.07-31.el7_6.10.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
noarch:
ghostscript-doc-9.07-31.el7_6.10.noarch.rpm
x86_64:
ghostscript-debuginfo-9.07-31.el7_6.10.i686.rpm
ghostscript-debuginfo-9.07-31.el7_6.10.x86_64.rpm
ghostscript-devel-9.07-31.el7_6.10.i686.rpm
ghostscript-devel-9.07-31.el7_6.10.x86_64.rpm
ghostscript-gtk-9.07-31.el7_6.10.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source:
ghostscript-9.07-31.el7_6.10.src.rpm
x86_64:
ghostscript-9.07-31.el7_6.10.i686.rpm
ghostscript-9.07-31.el7_6.10.x86_64.rpm
ghostscript-cups-9.07-31.el7_6.10.x86_64.rpm
ghostscript-debuginfo-9.07-31.el7_6.10.i686.rpm
ghostscript-debuginfo-9.07-31.el7_6.10.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
noarch:
ghostscript-doc-9.07-31.el7_6.10.noarch.rpm
x86_64:
ghostscript-debuginfo-9.07-31.el7_6.10.i686.rpm
ghostscript-debuginfo-9.07-31.el7_6.10.x86_64.rpm
ghostscript-devel-9.07-31.el7_6.10.i686.rpm
ghostscript-devel-9.07-31.el7_6.10.x86_64.rpm
Read the Full Advisory
An update for ghostscript is now available for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat Enterprise Linux Client (v. 7) - x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64
Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) - aarch64, ppc64le, s390x
Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - aarch64, noarch, ppc64le, s390x
1677581 - CVE-2019-3838 ghostscript: forceput in DefineResource is still accessible (700576)
1677588 - CVE-2019-3835 ghostscript: superexec operator is available (700585)
Get the latest Linux and open source security news straight to your inbox.