SUSE-SU-2018:3330-1
Dashboard / Vulnerabilities / SUSE-SU-2018:3330-1
SUSE-SU-2018:3330-1
Summary: Security update for ghostscript-library
Details: This update for ghostscript-library fixes the following issues: - CVE-2018-16511: A type confusion in 'ztype' could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact. (bsc#1107426) - CVE-2018-16540: Attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact. (bsc#1107420) - CVE-2018-16541: Attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter. (bsc#1107421) - CVE-2018-16542: Attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter. (bsc#1107413) - CVE-2018-16509: Incorrect 'restoration of privilege' checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the 'pipe' instruction. (bsc#1107410 - CVE-2018-16513: Attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact. (bsc#1107412) - CVE-2018-15910: Attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code. (bsc#1106173) - CVE-2017-9611: The Ins_MIRP function allowed remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document. (bsc#1050893)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183330-1/, https://bugzilla.suse.com/1050893, https://bugzilla.suse.com/1106173, https://bugzilla.suse.com/1107410, https://bugzilla.suse.com/1107412, https://bugzilla.suse.com/1107413, https://bugzilla.suse.com/1107420, https://bugzilla.suse.com/1107421, https://bugzilla.suse.com/1107426, https://www.suse.com/security/cve/CVE-2017-9611, https://www.suse.com/security/cve/CVE-2018-15910, https://www.suse.com/security/cve/CVE-2018-16509, https://www.suse.com/security/cve/CVE-2018-16511, https://www.suse.com/security/cve/CVE-2018-16513, https://www.suse.com/security/cve/CVE-2018-16540, https://www.suse.com/security/cve/CVE-2018-16541, https://www.suse.com/security/cve/CVE-2018-16542
Affected packages
Package
Name: ghostscript-library
Purl: pkg:rpm/suse/ghostscript-library&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
