ghostscript-8.70-11.AXS4.6

エラータID: AXSA:2012-100:01

Release date: 
Wednesday, February 8, 2012 - 12:24
Subject: 
ghostscript-8.70-11.AXS4.6
Affected Channels: 
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity: 
High
Description: 

Ghostscript is a set of software that provides a PostScript interpreter, a set of C procedures (the Ghostscript library, which implements the graphics capabilities in the PostScript language) and an interpreter for Portable Document Format (PDF) files. Ghostscript translates PostScript code into many common, bitmapped formats, like those understood by your printer or screen. Ghostscript is normally used to display PostScript files and to print PostScript files to non-PostScript printers.
If you need to display PostScript files or print them to non-PostScript printers, you should install ghostscript. If you install ghostscript, you also need to install the ghostscript-fonts package.
Security issues fixed with this release:
CVE-2009-3743
Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
CVE-2010-2055
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program.
CVE-2010-4054
The gs_type2_interpret function in Ghostscript allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) via crafted font data in a compressed data stream, aka bug 691043.
CVE-2010-4820
No description available at the time of writing, use the CVE link.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. ghostscript-8.70-11.AXS4.6.src.rpm
    MD5: 7c41fbc85f6c752b7ccf48cb47f1c3db
    SHA-256: 446dc6a1a8c27db1a86654581e025a805ece8f9185a5e53f38bd34406fb6b3af
    Size: 12.16 MB

Asianux Server 4 for x86
  1. ghostscript-8.70-11.AXS4.6.i686.rpm
    MD5: 567fec950a5fa64ad361a1587af3f2df
    SHA-256: 4bfb30872302ad9e4b43acd70eb70ba23e67b28b11f3912848a8251e6a2c50ba
    Size: 4.45 MB

Asianux Server 4 for x86_64
  1. ghostscript-8.70-11.AXS4.6.x86_64.rpm
    MD5: 7afda5aab5caf3880071c28d96f6a86b
    SHA-256: 2a027f5fe54ef875a8019b27e21d27ce3314943e0a09de11af4a113c90c0562f
    Size: 4.41 MB
  2. ghostscript-8.70-11.AXS4.6.i686.rpm
    MD5: 567fec950a5fa64ad361a1587af3f2df
    SHA-256: 4bfb30872302ad9e4b43acd70eb70ba23e67b28b11f3912848a8251e6a2c50ba
    Size: 4.45 MB