Alerts This Week
Warning Icon 1 758
Alerts This Week
Warning Icon 1 758

Ubuntu 18.10 USN-3866-3 Critical Ghostscript Regression Fix

ubuntu
Calendar Grey February 26, 2019
Dist Ubuntu Esm H88
=========================================================================Ubuntu Security Notice USN-
USN-3866-2 introduced a regression in Ghostscript.

Summary

USN-3866-2 introduced a regression in Ghostscript.

Software Description:

- ghostscript: PostScript and PDF interpreter

Details:

USN-3866-2 fixed a regression in Ghostscript. The Ghostscript update

introduced a new regression that resulted in certain pages being printed

with a blue background. This update fixes the problem.

Original advisory details:

Tavis Ormandy discovered that Ghostscript incorrectly handled certain

PostScript files. If a user or automated system were tricked into

processing a specially crafted file, a remote attacker could possibly use

this issue to access arbitrary files, execute arbitrary code, or cause a

denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
  ghostscript                     9.26~dfsg+0-0ubuntu0.18.10.7
  libgs9                          9.26~dfsg+0-0ubuntu0.18.10.7

Ubuntu 18.04 LTS:
  ghostscript                     9.26~dfsg+0-0ubuntu0.18.04.7
  libgs9                          9.26~dfsg+0-0ubuntu0.18.04.7

Ubuntu 16.04 LTS:
  ghostscript                     9.26~dfsg+0-0ubuntu0.16.04.7
  libgs9                          9.26~dfsg+0-0ubuntu0.16.04.7

Ubuntu 14.04 LTS:
  ghostscript                     9.26~dfsg+0-0ubuntu0.14.04.7
  libgs9                          9.26~dfsg+0-0ubuntu0.14.04.7

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3866-3

https://ubuntu.com/security/notices/USN-3866-1

https://bugs.launchpad.net/ubuntu/+source/ghostscript/+bug/1817308

Severity
critical
Lowest
Low
Medium
High
Critical

February 26, 2019

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here