Lucene search

K
ubuntuUbuntuUSN-501-2
HistoryOct 22, 2007 - 12:00 a.m.

Ghostscript vulnerability

2007-10-2200:00:00
ubuntu.com
38

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6.4

Confidence

Low

EPSS

0.058

Percentile

93.4%

Releases

  • Ubuntu 7.10
  • Ubuntu 7.04
  • Ubuntu 6.10

Packages

  • ghostscript -
  • gs-gpl -

Details

USN-501-1 fixed vulnerabilities in Jasper. This update provides the
corresponding update for the Jasper internal to Ghostscript.

Original advisory details:

It was discovered that Jasper did not correctly handle corrupted JPEG2000
images. By tricking a user into opening a specially crafted JPG, a
remote attacker could cause the application using libjasper to crash,
resulting in a denial of service.

OSVersionArchitecturePackageVersionFilename
Ubuntu7.10noarchlibgs8< 8.61.dfsg.1~svn8187-0ubuntu3.2UNKNOWN
Ubuntu7.10noarchghostscript< 8.61.dfsg.1~svn8187-0ubuntu3.2UNKNOWN
Ubuntu7.10noarchghostscript-x< 8.61.dfsg.1~svn8187-0ubuntu3.2UNKNOWN
Ubuntu7.10noarchlibgs-dev< 8.61.dfsg.1~svn8187-0ubuntu3.2UNKNOWN
Ubuntu7.04noarchgs-gpl< 8.54.dfsg.1-5ubuntu0.1UNKNOWN
Ubuntu6.10noarchgs-gpl< 8.50-1.1ubuntu1.1UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6.4

Confidence

Low

EPSS

0.058

Percentile

93.4%