gpp_maybe
Security update for ghostscript-library
SUSE-SLE-SAP-12-2016-1458
This update for ghostscript-library fixes the following issues: - Multiple security vulnerabilities have been discovered where ghostscript's "-dsafer" flag did not provide sufficient protection against unintended access to the file system. Thus, a machine that would process a specially crafted Postscript file would potentially leak sensitive information to an attacker. (CVE-2013-5653, bsc#1001951) - An incorrect reference count was found in .setdevice. This issue lead to a use-after-free scenario, which could have been exploited for denial-of-service or, possibly, arbitrary code execution attacks. (CVE-2016-7978, bsc#1001951) - Insufficient validation of the type of input in .initialize_dsc_parser used to allow remote code execution. (CVE-2016-7979, bsc#1001951)
-
Release DateOct 11 2016
-
References
-
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server for SAP Applications 12 x86_64
-
Packagesghostscript
The Ghostscript interpreter for PostScript and PDFghostscript-x119.15-11.1 lock rpm lock src
X11 library for Ghostscript9.15-11.1 lock rpm