Alerts This Week
Warning Icon 1 640
Alerts This Week
Warning Icon 1 640

Ubuntu: 3831-2 Moderate: Ghostscript Regression Fix and Update

ubuntu
Calendar Grey December 6, 2018
Dist Ubuntu Esm H88
=========================================================================Ubuntu Security Notice USN-
USN-3831-1 introduced a regression in Ghostscript.

Summary

USN-3831-1 introduced a regression in Ghostscript.

Software Description:

- ghostscript: PostScript and PDF interpreter

Details:

USN-3831-1 fixed vulnerabilities in Ghostscript. Ghostscript 9.26

introduced a regression when used with certain options. This update fixes

the problem.

Original advisory details:

It was discovered that Ghostscript contained multiple security issues. If a

user or automated system were tricked into processing a specially crafted

file, a remote attacker could possibly use these issues to access arbitrary

files, execute arbitrary code, or cause a denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
  ghostscript                     9.26~dfsg+0-0ubuntu0.18.10.3
  libgs9                          9.26~dfsg+0-0ubuntu0.18.10.3

Ubuntu 18.04 LTS:
  ghostscript                     9.26~dfsg+0-0ubuntu0.18.04.3
  libgs9                          9.26~dfsg+0-0ubuntu0.18.04.3

Ubuntu 16.04 LTS:
  ghostscript                     9.26~dfsg+0-0ubuntu0.16.04.3
  libgs9                          9.26~dfsg+0-0ubuntu0.16.04.3

Ubuntu 14.04 LTS:
  ghostscript                     9.26~dfsg+0-0ubuntu0.14.04.3
  libgs9                          9.26~dfsg+0-0ubuntu0.14.04.3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3831-1

https://bugs.launchpad.net/ubuntu/+source/ghostscript/+bug/1806517

Severity
important
Lowest
Low
Medium
High
Critical

December 06, 2018

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here