gpp_maybe
Security update for ghostscript
SUSE-SLE-SAP-12-2017-866
This update for ghostscript fixes the following security vulnerabilities: - CVE-2017-8291: A remote command execution and a -dSAFER bypass via a crafted .eps document were exploited in the wild. (bsc#1036453) - CVE-2016-9601: An integer overflow in the bundled jbig2dec library could have been misused to cause a Denial-of-Service. (bsc#1018128) - CVE-2016-10220: A NULL pointer dereference in the PDF Transparency module allowed remote attackers to cause a Denial-of-Service. (bsc#1032120) - CVE-2017-5951: A NULL pointer dereference allowed remote attackers to cause a denial of service via a crafted PostScript document. (bsc#1032114) - CVE-2017-7207: A NULL pointer dereference allowed remote attackers to cause a denial of service via a crafted PostScript document. (bsc#1030263) This is a reissue of the previous update to also include SUSE Linux Enterprise 12 GA LTSS packages.
-
Release DateMay 24 2017
-
ReferencesBugzilla: 1032120, 1032114, 1018128, 1030263, 1036453
CVEs: CVE-2017-5951, CVE-2016-10220, CVE-2017-7207, CVE-2017-8291, CVE-2016-9601 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server for SAP Applications 12 x86_64
-
Packagesghostscript
The Ghostscript interpreter for PostScript and PDFghostscript-x119.15-22.1 lock rpm lock src
X11 library for Ghostscript9.15-22.1 lock rpm