Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2018:3330-1 Important: Ghostscript Library Denial of Service Threat

suse
Calendar Grey October 23, 2018
Dist Suse Esm H88
SUSE Security Patch for ImageMagick addresses severe vulnerabilities. Implement this patch to ensure system integrity.
An update that fixes 8 vulnerabilities is now available

Summary

This update for ghostscript-library fixes the following issues: - CVE-2018-16511: A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact. (bsc#1107426) - CVE-2018-16540: Attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact. (bsc#1107420) - CVE-2018-16541: Attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter. (bsc#1107421) - CVE-2018-16542: Attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling

References

#1050893 #1106173 #1107410 #1107412 #1107413

#1107420 #1107421 #1107426

Cross- CVE-2017-9611 CVE-2018-15910 CVE-2018-16509

CVE-2018-16511 CVE-2018-16513 CVE-2018-16540

CVE-2018-16541 CVE-2018-16542

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2017-9611.html

https://www.suse.com/security/cve/CVE-2018-15910.html

https://www.suse.com/security/cve/CVE-2018-16509.html

https://www.suse.com/security/cve/CVE-2018-16511.html

https://www.suse.com/security/cve/CVE-2018-16513.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:3330-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here