Updated sigil package fixes security vulnerability: Mike Salvatore discovered that Sigil mishandled certain malformed EPUB files. An attacker could use this vulnerability to write arbitrary files to the filesystem (CVE-2019-14452). . MGASA-2019-0249 - Updated sigil packages fix security vulnerability Publication date: 06 Sep 2019 URL: https://advisories.mageia.org/MGASA-2019-0249.html Type: security Affected Mageia releases: 6, 7 CVE: CVE-2019-14452 Updated sigil package fixes security vulnerability: Mike Salvatore discovered that Sigil mishandled certain malformed EPUB files. An attacker could use this vulnerability to write arbitrary files to the filesystem (CVE-2019-14452). References: - https://bugs.mageia.org/show_bug.cgi?id=25290 - https://ubuntu.com/security/notices/USN-4085-1 - https://www.cve.org/CVERecord?id=CVE-2019-14452 SRPMS: - 6/core/sigil-0.9.16-1.mga6 - 7/core/sigil-0.9.16-1.mga7 . The latest Sigil release addresses a significant security vulnerability linked to improperly formatted EPUB documents that allowed unauthorized writes to the filesystem.. Sigil Security, Mageia Update, File System Threat, EPUB Vulnerability. . LinuxSecurity.com Team
Ghostscript could be made to access arbitrary files if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4111-1 August 29, 2019 ghostscript vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.04 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Ghostscript could be made to access arbitrary files if it opened a specially crafted file. Software Description: - ghostscript: PostScript and PDF interpreter Details: Hiroki Matsukuma discovered that the PDF interpreter in Ghostscript did not properly restrict privileged calls when ‘-dSAFER’ restrictions were in effect. If a user or automated system were tricked into processing a specially crafted file, a remote attacker could possibly use this issue to access arbitrary files. (CVE-2019-14811, CVE-2019-14812, CVE-2019-14813, CVE-2019-14817) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04: ghostscript 9.26~dfsg+0-0ubuntu7.3 libgs9 9.26~dfsg+0-0ubuntu7.3 Ubuntu 18.04 LTS: ghostscript 9.26~dfsg+0-0ubuntu0.18.04.11 libgs9 9.26~dfsg+0-0ubuntu0.18.04.11 Ubuntu 16.04 LTS: ghostscript 9.26~dfsg+0-0ubuntu0.16.04.11 libgs9 9.26~dfsg+0-0ubuntu0.16.04.11 In general, a standard system update will make all the necessary changes. References: CVE-2019-14811, CVE-2019-14812, CVE-2019-14813, CVE-2019-14817 Package Information: https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu7.3 https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.11 https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.11 . Recent Ghostscript flawsfound in Ubuntu may lead to unauthorized file access. Discover the security patches available and the process to update your systems.. Ghostscript Vulnerabilities, Ubuntu Security Notice, Arbitrary File Access, System Update Instructions, PostScript Interpreter. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.