ALT-PU-2023-1968-3
Package ghostscript updated to version 10.01.1-alt1 for branch p10 in task 320592.
Closed vulnerabilities
Modified: 2024-06-04
BDU:2022-00147
Уязвимость реализации функции sampled_data_finish() набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2025-03-19
BDU:2023-02055
Уязвимость набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, связанная с записью за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2021-45949
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=34675
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=2a3129365d3bc0d4a41f107ef175920d1505d1f7
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-803.yaml
- https://lists.debian.org/debian-lts-announce/2022/01/msg00006.html
- https://www.debian.org/security/2022/dsa-5038
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=34675
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=2a3129365d3bc0d4a41f107ef175920d1505d1f7
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-803.yaml
- https://lists.debian.org/debian-lts-announce/2022/01/msg00006.html
- https://www.debian.org/security/2022/dsa-5038
Modified: 2025-02-14
CVE-2023-28879
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.
- http://www.openwall.com/lists/oss-security/2023/04/12/4
- https://bugs.ghostscript.com/show_bug.cgi?id=706494
- https://ghostscript.readthedocs.io/en/latest/News.html
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=37ed5022cecd584de868933b5b60da2e995b3179
- https://lists.debian.org/debian-lts-announce/2023/04/msg00003.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CI6UCKM3XMK7PYNIRGAVDJ5VKN6XYZOE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DHJX62KSRIOBZA6FKONMJP7MEFY7LTH2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MADLP3GWJFLLFVNZGEDNPMDQR6CCXAHN/
- https://security.gentoo.org/glsa/202309-03
- https://www.debian.org/security/2023/dsa-5383
- http://www.openwall.com/lists/oss-security/2023/04/12/4
- https://bugs.ghostscript.com/show_bug.cgi?id=706494
- https://ghostscript.readthedocs.io/en/latest/News.html
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=37ed5022cecd584de868933b5b60da2e995b3179
- https://lists.debian.org/debian-lts-announce/2023/04/msg00003.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CI6UCKM3XMK7PYNIRGAVDJ5VKN6XYZOE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DHJX62KSRIOBZA6FKONMJP7MEFY7LTH2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MADLP3GWJFLLFVNZGEDNPMDQR6CCXAHN/
- https://security.gentoo.org/glsa/202309-03
- https://www.debian.org/security/2023/dsa-5383
