Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2024:3941-1 important: ghostscript multiple exploits

suse
Calendar Grey November 7, 2024
Dist Suse Esm H88
Crucial announcement regarding Ghostscript concerning significant security vulnerabilities related to potential code execution threats. Find the release specifics below.
* bsc#1232265 * bsc#1232267 * bsc#1232269 * bsc#1232270

Summary

## This update for ghostscript fixes the following issues: * CVE-2024-46951: Fixed arbitrary code execution via unchecked "Implementation" pointer in "Pattern" color space (bsc#1232265). * CVE-2024-46953: Fixed integer overflow when parsing the page format results in path truncation, path traversal, code execution (bsc#1232267). * CVE-2024-46956: Fixed arbitrary code execution via out of bounds data access in filenameforall (bsc#1232270). * CVE-2024-46955: Fixed out of bounds read when reading color in "Indexed" color space (bsc#1232269). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Retail Branch Server 4.3

References

* bsc#1232265

* bsc#1232267

* bsc#1232269

* bsc#1232270

Cross-

* CVE-2024-46951

* CVE-2024-46953

* CVE-2024-46955

* CVE-2024-46956

CVSS scores:

* CVE-2024-46951 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2024-46953 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2024-46955 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2024-46956 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* Basesystem Module 15-SP5

* Basesystem Module 15-SP6

* openSUSE Leap 15.5

* openSUSE Leap 15.6

* SUSE Enterprise Storage 7.1

* SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4

* SUSE Linux Enterprise Desktop 15 SP5

* SUSE Linux Enterprise Desktop 15 SP6

* SUSE Linux Enterprise High Performance Computing 15 SP2

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:3941-1
Release Date: 2024-11-07T10:11:36Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here