ALT-BU-2024-8272-3
Branch c10f1 update bulletin.
Package ghostscript updated to version 10.01.1-alt2 for branch c10f1 in task 348089.
Closed vulnerabilities
Modified: 2024-06-04
BDU:2022-00147
Уязвимость реализации функции sampled_data_finish() набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2025-03-19
BDU:2023-02055
Уязвимость набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, связанная с записью за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2021-45949
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=34675
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=2a3129365d3bc0d4a41f107ef175920d1505d1f7
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-803.yaml
- https://lists.debian.org/debian-lts-announce/2022/01/msg00006.html
- https://www.debian.org/security/2022/dsa-5038
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=34675
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=2a3129365d3bc0d4a41f107ef175920d1505d1f7
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-803.yaml
- https://lists.debian.org/debian-lts-announce/2022/01/msg00006.html
- https://www.debian.org/security/2022/dsa-5038
Modified: 2025-02-14
CVE-2023-28879
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.
- http://www.openwall.com/lists/oss-security/2023/04/12/4
- https://bugs.ghostscript.com/show_bug.cgi?id=706494
- https://ghostscript.readthedocs.io/en/latest/News.html
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=37ed5022cecd584de868933b5b60da2e995b3179
- https://lists.debian.org/debian-lts-announce/2023/04/msg00003.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CI6UCKM3XMK7PYNIRGAVDJ5VKN6XYZOE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DHJX62KSRIOBZA6FKONMJP7MEFY7LTH2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MADLP3GWJFLLFVNZGEDNPMDQR6CCXAHN/
- https://security.gentoo.org/glsa/202309-03
- https://www.debian.org/security/2023/dsa-5383
- http://www.openwall.com/lists/oss-security/2023/04/12/4
- https://bugs.ghostscript.com/show_bug.cgi?id=706494
- https://ghostscript.readthedocs.io/en/latest/News.html
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=37ed5022cecd584de868933b5b60da2e995b3179
- https://lists.debian.org/debian-lts-announce/2023/04/msg00003.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CI6UCKM3XMK7PYNIRGAVDJ5VKN6XYZOE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DHJX62KSRIOBZA6FKONMJP7MEFY7LTH2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MADLP3GWJFLLFVNZGEDNPMDQR6CCXAHN/
- https://security.gentoo.org/glsa/202309-03
- https://www.debian.org/security/2023/dsa-5383
Closed bugs
Артефакты генерации postscript, отсутствие текста на тестовой странице CUPS
