[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 1670-1] ghostscript security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : ghostscript
Version        : 9.26a~dfsg-0+deb8u1
CVE ID         : CVE-2019-6116

Tavis Ormandy discovered a vulnerability in Ghostscript, the GPL
PostScript/PDF interpreter, which may result in denial of service or the
execution of arbitrary code if a malformed Postscript file is processed
(despite the -dSAFER sandbox being enabled).

For Debian 8 "Jessie", this problem has been fixed in version
9.26a~dfsg-0+deb8u1.

We recommend that you upgrade your ghostscript packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAlxhOPcACgkQnUbEiOQ2
gwI9OQ/+IZ1ind4UeMXs1nlTahELEdQAzKOgtsPn51gl+2HW+PNIyYn0Offf4sHF
ck1TSwcl9F2OqEev6WHrPtxBVHXk64Xny3NN8DC/D4YddP3beemvS7lvtyXhQ5ob
G//D923qj4OSDfBjmIy3NQwnYgPpqKgFBFZ+gdPR6uZuOuHTu87MwE+BhqkJXZPN
yvwHl1lToPpueXrxuSV7KsO8D50Qu4lhu05bY4ifz6156aDC/JKprC8h3In7u2ct
NNd/OkKfwg4flpYk0wfxSmeWbxDc06ruaSpkZOYy9SxvqcfEFlk/pEePzxRwuNpl
SoscFTU0RAWWS+9JXRT+vavITZvypWTmIuaKtTL2m+KdEWYgEPH7HL73Vo+u/zgs
fT+SRn2KBpfB8JQJNuZnddBNj4w3f2E55JiW008iJBBvOVvyyo27Y9NG5W3mRV7a
3g9zRWZJ9dPDGrhQIHowMrx6cVxags7UhaVwn5CVAqtw3S87VrrD+1Y4TC8Q6L96
BFcsvGSo7l3cXFJ7/ulk0Lg3FC9t3RF+Rnkwl88Nx3vMD8vtXMwv5LRH8r8pFjzw
SxLLqFio66mG2+uNejNuCUk6YW9vFJFeP128YZOlMuamWrSug6Nq3E54/wMwNhjx
op7j77VZWvROc5NRduLGEXRJiQPHDqASd04aWXYM6fx24Mj7Fkw=
=onkV
-----END PGP SIGNATURE-----


Reply to: