## This update for ghostscript fixes the following issues: * CVE-2024-46951: Fixed arbitrary code execution via unchecked "Implementation" pointer in "Pattern" color space (bsc#1232265). * CVE-2024-46953: Fixed integer overflow when parsing the page format results in path truncation, path traversal, code execution (bsc#1232267). * CVE-2024-46956: Fixed arbitrary code execution via out of bounds data access in filenameforall (bsc#1232270). * CVE-2024-46955: Fixed out of bounds read when reading color in "Indexed" color space (bsc#1232269). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS 12-SP5
* bsc#1232265
* bsc#1232267
* bsc#1232269
* bsc#1232270
Cross-
* CVE-2024-46951
* CVE-2024-46953
* CVE-2024-46955
* CVE-2024-46956
CVSS scores:
* CVE-2024-46951 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2024-46953 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2024-46955 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2024-46956 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products:
* SUSE Linux Enterprise High Performance Computing 12 SP5
* SUSE Linux Enterprise Server 12 SP5
* SUSE Linux Enterprise Server 12 SP5 LTSS 12-SP5
* SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security 12-SP5
* SUSE Linux Enterprise Server for SAP Applications 12 SP5
An update that solves four vulnerabilities can now be installed.
Get the latest Linux and open source security news straight to your inbox.