Oval Definition:oval:org.opensuse.security:def:65457
Revision Date:2020-12-01Version:1
Title:Security update for ghostscript (Important)
Description:

This update for ghostscript fixes the following issues:

Security issues fixed:

- CVE-2019-3835: Fixed an unauthorized file system access caused by an available superexec operator. (bsc#1129180) - CVE-2019-3839: Fixed an unauthorized file system access caused by available privileged operators. (bsc#1134156) - CVE-2019-12973: Fixed a denial-of-service vulnerability in the OpenJPEG function opj_t1_encode_cblks. (bsc#1140359) - CVE-2019-14811: Fixed a safer mode bypass by .forceput exposure in .pdf_hook_DSC_Creator. (bsc#1146882) - CVE-2019-14812: Fixed a safer mode bypass by .forceput exposure in setuserparams. (bsc#1146882) - CVE-2019-14813: Fixed a safer mode bypass by .forceput exposure in setsystemparams. (bsc#1146882) - CVE-2019-14817: Fixed a safer mode bypass by .forceput exposure in .pdfexectoken and other procedures. (bsc#1146884)
Family:unixClass:patch
Status:Reference(s):1129180
1129186
1134156
1140359
1146882
1146884
1155419
1160471
1170441
CVE-2019-12973
CVE-2019-14811
CVE-2019-14812
CVE-2019-14813
CVE-2019-14817
CVE-2019-15681
CVE-2019-15690
CVE-2019-20788
CVE-2019-3835
CVE-2019-3839
SUSE-SU-2019:2460-1
SUSE-SU-2020:1164-1
Platform(s):SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 is installed
  • AND Package Information
  • ghostscript-mini-9.27-3.21 is installed
  • OR ghostscript-mini-devel-9.27-3.21 is installed
  • BACK