ghostscript-9.07-31.el7.1

エラータID: AXSA:2019-3605:01

Release date: 
Friday, February 15, 2019 - 14:24
Subject: 
ghostscript-9.07-31.el7.1
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

The Ghostscript suite contains utilities for rendering PostScript and PDF documents. Ghostscript translates PostScript code to common bitmap formats so that the code can be displayed or printed.

Security Fix(es):

* ghostscript: .tempfile file permission issues (699657) (CVE-2018-15908)

* ghostscript: shading_param incomplete type checking (699660) (CVE-2018-15909)

* ghostscript: missing type check in type checker (699659) (CVE-2018-16511)

* ghostscript: incorrect access checking in temp file handling to disclose contents of files (699658) (CVE-2018-16539)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Asianux would like to thank Tavis Ormandy (Google Project Zero) for reporting CVE-2018-15908.

CVE-2018-15908
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
CVE-2018-15909
In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
CVE-2018-16511
An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.
CVE-2018-16539
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. ghostscript-9.07-31.el7.1.src.rpm
    MD5: db34545565e80b81beafb06177de3104
    SHA-256: 572c0cfe37e1c4448f4ee3183d486c5f9722d0c1c72f94eec0a1bad214cb52e3
    Size: 26.59 MB

Asianux Server 7 for x86_64
  1. ghostscript-9.07-31.el7.1.x86_64.rpm
    MD5: 950a6019e6c11f2ad63b948b83d17406
    SHA-256: 04febb51da779a22fd21d50347c596a376b86c031b0b1c504a4514471cdee5ef
    Size: 4.31 MB
  2. ghostscript-cups-9.07-31.el7.1.x86_64.rpm
    MD5: 7efe533955465113c02b0572ebcbceaf
    SHA-256: 98c26afe8d430ff335b8fc57c5c9044476b13ab848564b8dc887cfd966f821a3
    Size: 56.36 kB
  3. ghostscript-9.07-31.el7.1.i686.rpm
    MD5: 353e0fa7cec679a3dfb1088753ebe976
    SHA-256: 06a4532185f0790c40cfc5602bfe20556f527c8ccd54fcb5bfa61aa90d16ec37
    Size: 4.31 MB