Netanel reported that the .buildfont1 procedure in Ghostscript, the GPL PostScript/PDF interpreter, does not properly restrict privileged calls, which could result in bypass of file system restrictions of the dSAFER sandbox. . Package : ghostscript Version : 9.26a~dfsg-0+deb8u4 CVE ID : CVE-2019-10216 Debian Bug : 934638 Netanel reported that the .buildfont1 procedure in Ghostscript, the GPL PostScript/PDF interpreter, does not properly restrict privileged calls, which could result in bypass of file system restrictions of the dSAFER sandbox. For Debian 8 "Jessie", this problem has been fixed in version 9.26a~dfsg-0+deb8u4. We recommend that you upgrade your ghostscript packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . ImageMagick security patch addresses remote code execution vulnerability in Ubuntu LTS installations. Update to version 8:6.9.7.4+dfsg-8ubuntu0.20.. Debian Security, Ghostscript Update, LTS Advisory, Sandbox Protection. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.