Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu: 3148-1 Critical: Ghostscript Denial Of Service And Info Disclosure

ubuntu
Calendar Grey December 2, 2016
Scroller Ubuntu
Recently, Ghostscript flaws were discovered in Ubuntu releases. Protect your devices immediately to avoid system freezes and safeguard your information.
Ghostscript could be made to crash, run programs, or disclose sensitiveinformation if it processed a specially crafted file.

Summary

Ghostscript could be made to crash, run programs, or disclose sensitive

information if it processed a specially crafted file.

Software Description:

- ghostscript: PostScript and PDF interpreter

Details:

Tavis Ormandy discovered multiple vulnerabilities in the way that Ghostscript

processes certain Postscript files. If a user or automated system were tricked

into opening a specially crafted file, an attacker could cause a denial of

service or possibly execute arbitrary code. (CVE-2016-7976, CVE-2016-7978,

CVE-2016-7979, CVE-2016-8602)

Multiple vulnerabilities were discovered in Ghostscript related to information

disclosure. If a user or automated system were tricked into opening a specially

crafted file, an attacker could expose sensitive data. (CVE-2013-5653,

CVE-2016-7977)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
  ghostscript                     9.19~dfsg+1-0ubuntu6.2
  ghostscript-x                   9.19~dfsg+1-0ubuntu6.2
  libgs9                          9.19~dfsg+1-0ubuntu6.2
  libgs9-common                   9.19~dfsg+1-0ubuntu6.2

Ubuntu 16.04 LTS:
  ghostscript                     9.18~dfsg~0-0ubuntu2.2
  ghostscript-x                   9.18~dfsg~0-0ubuntu2.2
  libgs9                          9.18~dfsg~0-0ubuntu2.2
  libgs9-common                   9.18~dfsg~0-0ubuntu2.2

Ubuntu 14.04 LTS:
  ghostscript                     9.10~dfsg-0ubuntu10.5
  ghostscript-x                   9.10~dfsg-0ubuntu10.5
  libgs9                          9.10~dfsg-0ubuntu10.5
  libgs9-common                   9.10~dfsg-0ubuntu10.5

Ubuntu 12.04 LTS:
  ghostscript                     9.05~dfsg-0ubuntu4.4
  ghostscript-x                   9.05~dfsg-0ubuntu4.4
  libgs9                          9.05~dfsg-0ubuntu4.4
  libgs9-common                   9.05~dfsg-0ubuntu4.4

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-3148-1

  CVE-2013-5653, CVE-2016-7976, CVE-2016-7977, CVE-2016-7978,

  CVE-2016-7979, CVE-2016-8602

Severity
critical
Lowest
Low
Medium
High
Critical

December 02, 2016

Package Information

  https://launchpad.net/ubuntu/+source/ghostscript/9.19~dfsg+1-0ubuntu6.2
  https://launchpad.net/ubuntu/+source/ghostscript/9.18~dfsg~0-0ubuntu2.2
  https://launchpad.net/ubuntu/+source/ghostscript/9.10~dfsg-0ubuntu10.5
  https://launchpad.net/ubuntu/+source/ghostscript/9.05~dfsg-0ubuntu4.4

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.