ALT-BU-2020-4108-1
Branch sisyphus update bulletin.
Closed vulnerabilities
BDU:2020-05385
Уязвимость библиотеки FreeType браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2020-05607
Уязвимость функции печати веб-браузера Google Chrome, позволяющая нарушителю выполнить произвольный код
BDU:2021-01474
Уязвимость обработчика PDF-содержимого PDFium браузера Google Chrome, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01475
Уязвимость модуля отображения Blink браузера Google Chrome, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01515
Уязвимость компонента media браузера Google Chrome, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2025-02-05
CVE-2020-15999
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- openSUSE-SU-2020:1829
- openSUSE-SU-2020:1829
- 20201118 TCMalloc viewer/dumper - TCMalloc Inspector Tool
- 20201118 TCMalloc viewer/dumper - TCMalloc Inspector Tool
- https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
- https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
- https://crbug.com/1139963
- https://crbug.com/1139963
- https://googleprojectzero.blogspot.com/p/rca-cve-2020-15999.html
- https://googleprojectzero.blogspot.com/p/rca-cve-2020-15999.html
- FEDORA-2020-6b35849edd
- FEDORA-2020-6b35849edd
- GLSA-202011-12
- GLSA-202011-12
- GLSA-202012-04
- GLSA-202012-04
- GLSA-202401-19
- GLSA-202401-19
- https://security.netapp.com/advisory/ntap-20240812-0001/
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-16000
Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- openSUSE-SU-2020:1829
- openSUSE-SU-2020:1829
- https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
- https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
- https://crbug.com/1125337
- https://crbug.com/1125337
- FEDORA-2020-8aca25b5c8
- FEDORA-2020-8aca25b5c8
- FEDORA-2020-127d40f1ab
- FEDORA-2020-127d40f1ab
- FEDORA-2020-4e8e48da22
- FEDORA-2020-4e8e48da22
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-16001
Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- openSUSE-SU-2020:1829
- openSUSE-SU-2020:1829
- https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
- https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
- https://crbug.com/1135018
- https://crbug.com/1135018
- FEDORA-2020-8aca25b5c8
- FEDORA-2020-8aca25b5c8
- FEDORA-2020-127d40f1ab
- FEDORA-2020-127d40f1ab
- FEDORA-2020-4e8e48da22
- FEDORA-2020-4e8e48da22
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-16002
Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
- openSUSE-SU-2020:1829
- openSUSE-SU-2020:1829
- https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
- https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
- https://crbug.com/1137630
- https://crbug.com/1137630
- FEDORA-2020-8aca25b5c8
- FEDORA-2020-8aca25b5c8
- FEDORA-2020-127d40f1ab
- FEDORA-2020-127d40f1ab
- FEDORA-2020-4e8e48da22
- FEDORA-2020-4e8e48da22
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Modified: 2024-11-21
CVE-2020-16003
Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- openSUSE-SU-2020:1829
- openSUSE-SU-2020:1829
- https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
- https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
- https://crbug.com/1134960
- https://crbug.com/1134960
- FEDORA-2020-8aca25b5c8
- FEDORA-2020-8aca25b5c8
- FEDORA-2020-127d40f1ab
- FEDORA-2020-127d40f1ab
- FEDORA-2020-4e8e48da22
- FEDORA-2020-4e8e48da22
- GLSA-202101-30
- GLSA-202101-30
- DSA-4824
- DSA-4824
Package ghostscript updated to version 9.53.3-alt1 for branch sisyphus in task 260366.
Closed vulnerabilities
BDU:2019-03223
Уязвимость процедуры .buildfont1 программы конвертирования файлов формата PostScript Ghostscript, позволяющая нарушителю повысить свои привилегии и получить доступ к файловой системе
BDU:2019-03225
Уязвимость процедуры .pdf_hook_DSC_Creator программы конвертирования файлов формата PostScript Ghostscript, позволяющая нарушителю получить доступ к файловой системе
BDU:2019-03226
Уязвимость процедуры .setuserparams2 программы конвертирования файлов формата PostScript Ghostscript, позволяющая нарушителю выполнить произвольные команды или получить доступ к файловой системе
BDU:2019-03227
Уязвимость процедуры setsystemparams программы конвертирования файлов формата PostScript Ghostscript, позволяющая нарушителю выполнить произвольные команды или получить доступ к файловой системе
BDU:2019-03228
Уязвимость процедуры .pdfexectoken программы конвертирования файлов формата PostScript Ghostscript, позволяющая нарушителю выполнить произвольные команды или получить доступ к файловой системе
BDU:2020-01769
Уязвимость процедуры .charkeys интерпретатора PostScript/PDF Ghostscript, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01141
Уязвимость функции bj10v_print_page() (contrib/japanese/gdev10v.c) набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01143
Уязвимость функции compose_group_nonknockout_nonblend_isolated_allmask_common() (base/gxblend.c) набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01144
Уязвимость функции p_print_image() (devices/gdevcdj.c) набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01146
Уязвимость функции clj_media_size() (devices/gdevclj.c) набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01147
Уязвимость функции mj_raster_cmd() (contrib/japanese/gdevmjc.c) набора программного обеспечения для обработки преобразования и генерации документов Ghostscript связанная с записью за границами буфера, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01151
Уязвимость функции FloydSteinbergDitheringC() (contrib/gdevbjca.c) набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01152
Уязвимость функции tiff12_print_page() (devices/gdevtfnx.c) набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01153
Уязвимость функции epsc_print_page() (devices/gdevepsc.c) набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01154
Уязвимость функции GetNumWrongData() (contrib/lips4/gdevlips.c) набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01155
Уязвимость компонента contrib/gdevdj9.c набора программного обеспечения для обработки, преобразования и генерации документов, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01156
Уязвимость функции cif_print_page() набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01157
Уязвимость функции mj_color_correct() набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01163
Уязвимость функции lprn_is_black() (contrib/lips4/gdevlprn.c) набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01164
Уязвимость функции okiibm_print_page1() (devices/gdevokii.c) набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01166
Уязвимость функции jetp3852_print_page() (devices/gdev3852.c) набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01168
Уязвимость функции pj_common_print_page() (devices/gdevpjet.c) набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, связанная с переполнением буфера, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-10216
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.
Modified: 2024-11-21
CVE-2019-14811
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
- openSUSE-SU-2019:2223
- openSUSE-SU-2019:2223
- openSUSE-SU-2019:2222
- openSUSE-SU-2019:2222
- RHBA-2019:2824
- RHBA-2019:2824
- RHSA-2019:2594
- RHSA-2019:2594
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14811
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14811
- [debian-lts-announce] 20190909 [SECURITY] [DLA 1915-1] ghostscript security update
- [debian-lts-announce] 20190909 [SECURITY] [DLA 1915-1] ghostscript security update
- FEDORA-2019-ebd6c4f15a
- FEDORA-2019-ebd6c4f15a
- FEDORA-2019-0a9d525d71
- FEDORA-2019-0a9d525d71
- FEDORA-2019-953fc0f16d
- FEDORA-2019-953fc0f16d
- 20190910 [SECURITY] [DSA 4518-1] ghostscript security update
- 20190910 [SECURITY] [DSA 4518-1] ghostscript security update
- GLSA-202004-03
- GLSA-202004-03
- DSA-4518
- DSA-4518
Modified: 2024-11-21
CVE-2019-14812
A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=885444fcbe10dc42787ecb76686c8ee4dd33bf33
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=885444fcbe10dc42787ecb76686c8ee4dd33bf33
- https://access.redhat.com/security/cve/cve-2019-14812
- https://access.redhat.com/security/cve/cve-2019-14812
- https://bugs.ghostscript.com/show_bug.cgi?id=701444
- https://bugs.ghostscript.com/show_bug.cgi?id=701444
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14812
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14812
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LBUC4DBBJTRFNCR3IODBV4IXB2C2HI3V/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LBUC4DBBJTRFNCR3IODBV4IXB2C2HI3V/
- GLSA-202004-03
- GLSA-202004-03
Modified: 2024-11-21
CVE-2019-14813
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=885444fcbe10dc42787ecb76686c8ee4dd33bf33
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=885444fcbe10dc42787ecb76686c8ee4dd33bf33
- openSUSE-SU-2019:2223
- openSUSE-SU-2019:2223
- openSUSE-SU-2019:2222
- openSUSE-SU-2019:2222
- RHBA-2019:2824
- RHBA-2019:2824
- RHSA-2019:2594
- RHSA-2019:2594
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14813
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14813
- [debian-lts-announce] 20190909 [SECURITY] [DLA 1915-1] ghostscript security update
- [debian-lts-announce] 20190909 [SECURITY] [DLA 1915-1] ghostscript security update
- FEDORA-2019-ebd6c4f15a
- FEDORA-2019-ebd6c4f15a
- FEDORA-2019-0a9d525d71
- FEDORA-2019-0a9d525d71
- FEDORA-2019-953fc0f16d
- FEDORA-2019-953fc0f16d
- 20190910 [SECURITY] [DSA 4518-1] ghostscript security update
- 20190910 [SECURITY] [DSA 4518-1] ghostscript security update
- GLSA-202004-03
- GLSA-202004-03
- DSA-4518
- DSA-4518
Modified: 2024-11-21
CVE-2019-14817
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=cd1b1cacadac2479e291efe611979bdc1b3bdb19
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=cd1b1cacadac2479e291efe611979bdc1b3bdb19
- openSUSE-SU-2019:2223
- openSUSE-SU-2019:2223
- openSUSE-SU-2019:2222
- openSUSE-SU-2019:2222
- RHBA-2019:2824
- RHBA-2019:2824
- RHSA-2019:2594
- RHSA-2019:2594
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14817
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14817
- [debian-lts-announce] 20190909 [SECURITY] [DLA 1915-1] ghostscript security update
- [debian-lts-announce] 20190909 [SECURITY] [DLA 1915-1] ghostscript security update
- FEDORA-2019-ebd6c4f15a
- FEDORA-2019-ebd6c4f15a
- FEDORA-2019-0a9d525d71
- FEDORA-2019-0a9d525d71
- FEDORA-2019-953fc0f16d
- FEDORA-2019-953fc0f16d
- 20190910 [SECURITY] [DSA 4518-1] ghostscript security update
- 20190910 [SECURITY] [DSA 4518-1] ghostscript security update
- GLSA-202004-03
- GLSA-202004-03
- DSA-4518
- DSA-4518
Modified: 2024-11-21
CVE-2019-14869
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access files outside of restricted areas or execute commands.
- JVN#52486659
- JVN#52486659
- openSUSE-SU-2019:2534
- openSUSE-SU-2019:2534
- openSUSE-SU-2019:2535
- openSUSE-SU-2019:2535
- [oss-security] 20191115 CVE-2019-14869 ghostscript: -dSAFER escape in .charkeys
- [oss-security] 20191115 CVE-2019-14869 ghostscript: -dSAFER escape in .charkeys
- RHSA-2020:0222
- RHSA-2020:0222
- https://bugs.ghostscript.com/show_bug.cgi?id=701841
- https://bugs.ghostscript.com/show_bug.cgi?id=701841
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14869
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14869
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=485904772c5f
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=485904772c5f
- FEDORA-2019-7debdd1807
- FEDORA-2019-7debdd1807
- FEDORA-2019-6cdb10aa59
- FEDORA-2019-6cdb10aa59
- FEDORA-2019-17f42f585a
- FEDORA-2019-17f42f585a
- 20191118 [SECURITY] [DSA 4569-1] ghostscript security update
- 20191118 [SECURITY] [DSA 4569-1] ghostscript security update
Modified: 2024-11-21
CVE-2020-16287
A buffer overflow vulnerability in lprn_is_black() in contrib/lips4/gdevlprn.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- https://bugs.ghostscript.com/show_bug.cgi?id=701785
- https://bugs.ghostscript.com/show_bug.cgi?id=701785
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=450da26a76286a8342ec0864b3d113856709f8f6
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=450da26a76286a8342ec0864b3d113856709f8f6
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2024-11-21
CVE-2020-16288
A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- http://git.ghostscript.com/?p=ghostpdl.git%3Bh=aba3375ac24f8e02659d9b1eb9093909618cdb9f
- http://git.ghostscript.com/?p=ghostpdl.git%3Bh=aba3375ac24f8e02659d9b1eb9093909618cdb9f
- https://bugs.ghostscript.com/show_bug.cgi?id=701791
- https://bugs.ghostscript.com/show_bug.cgi?id=701791
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2024-11-21
CVE-2020-16289
A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- https://bugs.ghostscript.com/show_bug.cgi?id=701788
- https://bugs.ghostscript.com/show_bug.cgi?id=701788
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=d31e25ed5b130499e0d880e4609b1b4824699768
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=d31e25ed5b130499e0d880e4609b1b4824699768
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2024-11-21
CVE-2020-16290
A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- http://git.ghostscript.com/?p=ghostpdl.git%3Bh=93cb0c0adbd9bcfefd021d59c472388f67d3300d
- http://git.ghostscript.com/?p=ghostpdl.git%3Bh=93cb0c0adbd9bcfefd021d59c472388f67d3300d
- https://bugs.ghostscript.com/show_bug.cgi?id=701786
- https://bugs.ghostscript.com/show_bug.cgi?id=701786
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2025-03-14
CVE-2020-16291
A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- http://git.ghostscript.com/?p=ghostpdl.git%3Bh=4f73e8b4d578e69a17f452fa60d2130c5faaefd6
- http://git.ghostscript.com/?p=ghostpdl.git;h=4f73e8b4d578e69a17f452fa60d2130c5faaefd6
- https://bugs.ghostscript.com/show_bug.cgi?id=701787
- https://bugs.ghostscript.com/show_bug.cgi?id=701787
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=4f73e8b4d578e69a17f452fa60d2130c5faaefd6
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/tree/contrib/gdevdj9.c?h=ghostpdl-9.18#n824
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2024-11-21
CVE-2020-16292
A buffer overflow vulnerability in mj_raster_cmd() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- https://bugs.ghostscript.com/show_bug.cgi?id=701793
- https://bugs.ghostscript.com/show_bug.cgi?id=701793
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=863ada11f9a942a622a581312e2be022d9e2a6f7
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=863ada11f9a942a622a581312e2be022d9e2a6f7
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2024-11-21
CVE-2020-16293
A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- https://bugs.ghostscript.com/show_bug.cgi?id=701795
- https://bugs.ghostscript.com/show_bug.cgi?id=701795
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=7870f4951bcc6a153f317e3439e14d0e929fd231
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=7870f4951bcc6a153f317e3439e14d0e929fd231
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2024-11-21
CVE-2020-16294
A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- https://bugs.ghostscript.com/show_bug.cgi?id=701794
- https://bugs.ghostscript.com/show_bug.cgi?id=701794
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=89f58f1aa95b3482cadf6977da49457194ee5358
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=89f58f1aa95b3482cadf6977da49457194ee5358
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2024-11-21
CVE-2020-16295
A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- http://git.ghostscript.com/?p=ghostpdl.git%3Bh=2c2dc335c212750e0fb8ae157063bc06cafa8d3e
- http://git.ghostscript.com/?p=ghostpdl.git%3Bh=2c2dc335c212750e0fb8ae157063bc06cafa8d3e
- https://bugs.ghostscript.com/show_bug.cgi?id=701796
- https://bugs.ghostscript.com/show_bug.cgi?id=701796
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2025-03-25
CVE-2020-16296
A buffer overflow vulnerability in GetNumWrongData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- https://bugs.ghostscript.com/show_bug.cgi?id=701792
- https://bugs.ghostscript.com/show_bug.cgi?id=701792
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/tree/contrib/lips4/gdevlips.c?h=ghostscript-9.18#n163
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=9f39ed4a92578a020ae10459643e1fe72573d134
- https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=9f39ed4a92578a020ae10459643e1fe72573d134
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2025-03-14
CVE-2020-16297
A buffer overflow vulnerability in FloydSteinbergDitheringC() in contrib/gdevbjca.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- https://bugs.ghostscript.com/show_bug.cgi?id=701800
- https://bugs.ghostscript.com/show_bug.cgi?id=701800
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=bf72f1a3dd5392ee8291e3b1518a0c2c5dc6ba39
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/tree/contrib/gdevbjca.c?h=ghostpdl-9.18#n659
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=bf72f1a3dd5392ee8291e3b1518a0c2c5dc6ba39
- https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=bf72f1a3dd5392ee8291e3b1518a0c2c5dc6ba39
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2024-11-21
CVE-2020-16298
A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- https://bugs.ghostscript.com/show_bug.cgi?id=701799
- https://bugs.ghostscript.com/show_bug.cgi?id=701799
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=849e74e5ab450dd581942192da7101e0664fa5af
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=849e74e5ab450dd581942192da7101e0664fa5af
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2024-11-21
CVE-2020-16299
A Division by Zero vulnerability in bj10v_print_page() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- https://bugs.ghostscript.com/show_bug.cgi?id=701801
- https://bugs.ghostscript.com/show_bug.cgi?id=701801
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=19cebe708b9ee3d9e0f8bcdd79dbc6ef9ddc70d2
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=19cebe708b9ee3d9e0f8bcdd79dbc6ef9ddc70d2
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=4fcbece46870
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=4fcbece46870
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2024-11-21
CVE-2020-16300
A buffer overflow vulnerability in tiff12_print_page() in devices/gdevtfnx.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- https://bugs.ghostscript.com/show_bug.cgi?id=701807
- https://bugs.ghostscript.com/show_bug.cgi?id=701807
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=714e8995cd582d418276915cbbec3c70711fb19e
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=714e8995cd582d418276915cbbec3c70711fb19e
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2024-11-21
CVE-2020-16301
A buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- https://bugs.ghostscript.com/show_bug.cgi?id=701808
- https://bugs.ghostscript.com/show_bug.cgi?id=701808
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=f54414c8b15b2c27d1dcadd92cfe84f6d15f18dc
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=f54414c8b15b2c27d1dcadd92cfe84f6d15f18dc
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2024-11-21
CVE-2020-16308
A buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
- https://bugs.ghostscript.com/show_bug.cgi?id=701829
- https://bugs.ghostscript.com/show_bug.cgi?id=701829
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=af004276fd8f6c305727183c159b83021020f7d6
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=af004276fd8f6c305727183c159b83021020f7d6
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- [debian-lts-announce] 20200820 [SECURITY] [DLA 2335-1] ghostscript security update
- GLSA-202008-20
- GLSA-202008-20
- USN-4469-1
- USN-4469-1
- DSA-4748
- DSA-4748
Modified: 2024-11-21
CVE-2020-27792
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.
- https://access.redhat.com/security/cve/CVE-2020-27792
- https://access.redhat.com/security/cve/CVE-2020-27792
- https://bugs.ghostscript.com/show_bug.cgi?id=701844
- RHBZ#2247179
- RHBZ#2247179
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=4f6bc662909ab79e8fbe9822afb36e8a0eafc2b7
- https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=4f6bc662909ab79e8fbe9822afb36e8a0eafc2b7
- https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=4f6bc662909ab79e8fbe9822afb36e8a0eafc2b7
- [debian-lts-announce] 20220903 [SECURITY] [DLA 3096-1] ghostscript security update