gpp_maybe Security update for ghostscript-library
SUSE-SLE-SERVER-12-2016-1458


This update for ghostscript-library fixes the following issues: - Multiple security vulnerabilities have been discovered where ghostscript's "-dsafer" flag did not provide sufficient protection against unintended access to the file system. Thus, a machine that would process a specially crafted Postscript file would potentially leak sensitive information to an attacker. (CVE-2013-5653, bsc#1001951) - An incorrect reference count was found in .setdevice. This issue lead to a use-after-free scenario, which could have been exploited for denial-of-service or, possibly, arbitrary code execution attacks. (CVE-2016-7978, bsc#1001951) - Insufficient validation of the type of input in .initialize_dsc_parser used to allow remote code execution. (CVE-2016-7979, bsc#1001951)


cloud_download Downloads

SUSE Linux Enterprise Server LTSS 12 x86_64
  • Packages
    ghostscript
    The Ghostscript interpreter for PostScript and PDF
    9.15-11.1 lock rpm lock src
    ghostscript-x11
    X11 library for Ghostscript
    9.15-11.1 lock rpm
SUSE Linux Enterprise Server LTSS 12 s390x
  • Packages
    ghostscript
    The Ghostscript interpreter for PostScript and PDF
    9.15-11.1 lock rpm lock src
    ghostscript-x11
    X11 library for Ghostscript
    9.15-11.1 lock rpm