Lucene search

K
centosCentOS ProjectCESA-2019:0633
HistoryMar 25, 2019 - 5:33 p.m.

ghostscript security update

2019-03-2517:33:17
CentOS Project
lists.centos.org
141

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

59.9%

CentOS Errata and Security Advisory CESA-2019:0633

The Ghostscript suite contains utilities for rendering PostScript and PDF documents. Ghostscript translates PostScript code to common bitmap formats so that the code can be displayed or printed.

Security Fix(es):

  • ghostscript: superexec operator is available (700585) (CVE-2019-3835)

  • ghostscript: forceput in DefineResource is still accessible (700576) (CVE-2019-3838)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • ghostscript: Regression: double comment chars ‘%%’ in gs_init.ps leading to missing metadata (BZ#1673915)

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2019-March/085413.html

Affected packages:
ghostscript
ghostscript-cups
ghostscript-devel
ghostscript-doc
ghostscript-gtk

Upstream details at:
https://access.redhat.com/errata/RHSA-2019:0633

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

59.9%