USN-3148-1
Dashboard / Vulnerabilities / USN-3148-1
USN-3148-1
Summary: ghostscript vulnerabilities
Details: Tavis Ormandy discovered multiple vulnerabilities in the way that Ghostscript processes certain Postscript files. If a user or automated system were tricked into opening a specially crafted file, an attacker could cause a denial of service or possibly execute arbitrary code. (CVE-2016-7976, CVE-2016-7978, CVE-2016-7979, CVE-2016-8602) Multiple vulnerabilities were discovered in Ghostscript related to information disclosure. If a user or automated system were tricked into opening a specially crafted file, an attacker could expose sensitive data. (CVE-2013-5653, CVE-2016-7977)
References: https://ubuntu.com/security/notices/USN-3148-1, https://ubuntu.com/security/CVE-2013-5653, https://ubuntu.com/security/CVE-2016-7976, https://ubuntu.com/security/CVE-2016-7977, https://ubuntu.com/security/CVE-2016-7978, https://ubuntu.com/security/CVE-2016-7979, https://ubuntu.com/security/CVE-2016-8602
Affected packages
Package
Name: ghostscript
Purl: pkg:deb/ubuntu/[email protected]~dfsg-0ubuntu10.5?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
