Tuesday, November 12, 2024

[USN-7103-1] Ghostscript vulnerabilities

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmczoCoACgkQZWnYVadE
vpMKIg/+I7GLIhnxdqIWNPB+mJiiCif9XXTrysaCKMupU7Vn/4bfoMFKyqXlLYWL
Cov6dwWaEunfQ+cuHAhdw6FEOj2apupeebidwnDuT0BX7I68tK2+iX6NpEAAKiKq
SkXWYsC5v6why0XZwF4t0v0u/5O4Ihla3IIMMhfyOQQDtRYQZvGpvu/x3migNzrn
LV2jTi1S136c5yhNMScyrT7jzLV7Ba5YLQY0s8LRtAiT+oUVMawkrCyxtVLKqCp7
Pklj/vVVemT8lIr5VeYr61TkaMwM4YKwnxMuzEXmWNSZQx7+E6Plb+FavNXxKW+9
NqeboK0xFNdM3TUdAURAKaBwoPjexAFy77hke2PGsTZzxEYJy+v9QD8uHCdgV3qI
6s4l2RXHCvDbradeQZlcx+uos/juMIJW4Sxx7iKecpiSA6vHTEhepJJStyMsjF39
V2N5WtogAJStPTM2AJQX299GHKcC7KSl9jZ0fRxOSJCoSbQcYaoY/gURziSmcl/6
NMSApyykwrweZmBdyQbkDTgUb1PL+PVNvNDP3VsplLToVbsE/Sq3uMfaBv2ElLsl
+LeOe5dWlyf5GefdKF3sHVJ0nh+6EK/LZeDEPNCyqk3FuE0jnpWPX9acvI2tpXlP
jUCl53bZ7iqruikA3zRRk01cFYzxkVNK24N8QXVnuzOndc6gr3o=
=Ujic
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7103-1
November 12, 2024

ghostscript vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in Ghostscript.

Software Description:
- ghostscript: PostScript and PDF interpreter

Details:

It was discovered that Ghostscript incorrectly handled parsing certain PS
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-46951, CVE-2024-46953, CVE-2024-46955, CVE-2024-46956)

It was discovered that Ghostscript incorrectly handled parsing certain PDF
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 24.10.
(CVE-2024-46952)

It was discovered that Ghostscript incorrectly handled parsing certain PS
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly bypass file path validation.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 24.10.
(CVE-2024-46954)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
ghostscript 10.03.1~dfsg1-0ubuntu2.1
libgs10 10.03.1~dfsg1-0ubuntu2.1

Ubuntu 24.04 LTS
ghostscript 10.02.1~dfsg1-0ubuntu7.4
libgs10 10.02.1~dfsg1-0ubuntu7.4

Ubuntu 22.04 LTS
ghostscript 9.55.0~dfsg1-0ubuntu5.10
libgs9 9.55.0~dfsg1-0ubuntu5.10

Ubuntu 20.04 LTS
ghostscript 9.50~dfsg-5ubuntu4.14
libgs9 9.50~dfsg-5ubuntu4.14

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7103-1
CVE-2024-46951, CVE-2024-46952, CVE-2024-46953, CVE-2024-46954,
CVE-2024-46955, CVE-2024-46956

Package Information:
https://launchpad.net/ubuntu/+source/ghostscript/10.03.1~dfsg1-0ubuntu2.1
https://launchpad.net/ubuntu/+source/ghostscript/10.02.1~dfsg1-0ubuntu7.4
https://launchpad.net/ubuntu/+source/ghostscript/9.55.0~dfsg1-0ubuntu5.10
https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.14

No comments:

Post a Comment