USN-3403-1
Dashboard / Vulnerabilities / USN-3403-1
USN-3403-1
Summary: ghostscript vulnerabilities
Details: Kamil Frankowicz discovered that Ghostscript mishandles references. A remote attacker could use this to cause a denial of service. (CVE-2017-11714) Kim Gwan Yeong discovered that Ghostscript could allow a heap-based buffer over-read and application crash. A remote attacker could use a crafted document to cause a denial of service. (CVE-2017-9611, CVE-2017-9726, CVE-2017-9727, CVE-2017-9739) Kim Gwan Yeong discovered an use-after-free vulnerability in Ghostscript. A remote attacker could use a crafted file to cause a denial of service. (CVE-2017-9612) Kim Gwan Yeong discovered a lack of integer overflow check in Ghostscript. A remote attacker could use crafted PostScript document to cause a denial of service. (CVE-2017-9835)
References: https://ubuntu.com/security/notices/USN-3403-1, https://ubuntu.com/security/CVE-2017-9611, https://ubuntu.com/security/CVE-2017-9612, https://ubuntu.com/security/CVE-2017-9726, https://ubuntu.com/security/CVE-2017-9727, https://ubuntu.com/security/CVE-2017-9739, https://ubuntu.com/security/CVE-2017-9835, https://ubuntu.com/security/CVE-2017-11714
Affected packages
Package
Name: ghostscript
Purl: pkg:deb/ubuntu/[email protected]~dfsg-0ubuntu10.10?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
