You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa ghostscript

Sigurnosni nedostaci programskog paketa ghostscript

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4686-1
January 07, 2021

ghostscript vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in Ghostscript.

Software Description:
– ghostscript: PostScript and PDF interpreter

Details:

It was discovered that Ghostscript incorrectly handled certain image
files. If a user or automated system were tricked into processing a
specially crafted file, a remote attacker could use this issue to cause
Ghostscript to crash, resulting in a denial of service, or possibly
execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
ghostscript 9.26~dfsg+0-0ubuntu0.18.04.14
libgs9 9.26~dfsg+0-0ubuntu0.18.04.14

Ubuntu 16.04 LTS:
ghostscript 9.26~dfsg+0-0ubuntu0.16.04.14
libgs9 9.26~dfsg+0-0ubuntu0.16.04.14

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4686-1
CVE-2018-5727, CVE-2020-27814, CVE-2020-27824, CVE-2020-27841,
CVE-2020-27842, CVE-2020-27843, CVE-2020-27845, CVE-2020-6851,
CVE-2020-8112

Package Information:
https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.14
https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.14

—–BEGIN PGP SIGNATURE—–

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl/3LmsACgkQZWnYVadE
vpMWSw//VWOmerHPGo3oG7npmdzqJ5DK8/FAX8vi72QJFfqXJ4r+xIcQtPSoHmuL
at7jkaRRn+fZkKxRkE67DbxGiBCtntTrKZx8yHwKutSjQicxeVQXh7ZRO4B5zZMq
7jxSSTW+eModXJId7iXVbssCdRbLUfPp1c+uHm6rO7H2a2AuYRga7SyOeh4PkE2s
gdqAwhoTWjwqPCTWDoTtZKzE0MFsCUmMpgijSR71J4INqpHQCkxTGNG6+yScriHp
M8d+6aaeG/mWRJ1zplO6RZLDLfvfgPcsnBfz2wrgYPv044K8IN2s4kYIo3me1qT7
7j3s/YZnnE00sNtHAdFanSMvtmnvDombpFgMxtccnVhxGyyfhQJC5MVc6z+ql8e0
l0XjI8TfEitYBH2KCXEPOjoawM7xdYWfvwrELNlP57U0TnVrmUocKVYGACffN560
oufBMaLAd/tZT4g+h+/TA03OL5sIP4F+t/QFWyUgUHVzINdhJDI1J7hB4htTT8M8
E1aVHVfehm0CwT5MfKnHzg2mbzxAk0RKu4/5Ax8WYTVHCA9pup1p46fjxAHLWnKb
uXqzdNtcybY03yWMTjk6diqzntQLB1XrhSbBFLxsFqrCccI5V23xSsfj90EHmjlR
FPKOvzV6a8PBm/ovBYTnu3i1Om37Z1IEvO8tsuzR61pZGQeIWnw=
=0pqX
—–END PGP SIGNATURE—–

AutorDona Šeruga
Cert idNCERT-REF-2021-01-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa edk2

Otkriveni su sigurnosni nedostaci u programskom paketu edk2 za operacijski sustav Ubuntu. Otkriveni nedostaci potencijalnim napadačima omogućuju izazivanje DoS stanja...

Close