Revision Date: | 2019-09-26 | Version: | 1 |
Title: | Security update for ghostscript (Important) |
Description: |
This update for ghostscript to 9.27 fixes the following issues:
Security issues fixed:
- CVE-2019-3835: Fixed an unauthorized file system access caused by an available superexec operator. (bsc#1129180) - CVE-2019-3839: Fixed an unauthorized file system access caused by available privileged operators. (bsc#1134156) - CVE-2019-12973: Fixed a denial-of-service vulnerability in the OpenJPEG function opj_t1_encode_cblks. (bsc#1140359) - CVE-2019-14811: Fixed a safer mode bypass by .forceput exposure in .pdf_hook_DSC_Creator. (bsc#1146882) - CVE-2019-14812: Fixed a safer mode bypass by .forceput exposure in setuserparams. (bsc#1146882) - CVE-2019-14813: Fixed a safer mode bypass by .forceput exposure in setsystemparams. (bsc#1146882) - CVE-2019-14817: Fixed a safer mode bypass by .forceput exposure in .pdfexectoken and other procedures. (bsc#1146884)
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1129180 1131863 1134156 1140359 1146882 1146884 CVE-2019-12973 CVE-2019-14811 CVE-2019-14812 CVE-2019-14813 CVE-2019-14817 CVE-2019-3835 CVE-2019-3839 SUSE-SU-2019:2478-1
|
Platform(s): | SUSE OpenStack Cloud 8
| Product(s): | |
Definition Synopsis |
SUSE OpenStack Cloud 8 is installed AND Package Information
ghostscript-9.27-23.28.1 is installed
OR ghostscript-x11-9.27-23.28.1 is installed
|