From a24567fbc43f221b14e805f9bc0b7c6d16911c46 Mon Sep 17 00:00:00 2001 From: Alex Legler Date: Sun, 8 Mar 2015 22:02:38 +0100 Subject: Import existing advisories --- glsa-201412-17.xml | 64 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 64 insertions(+) create mode 100644 glsa-201412-17.xml (limited to 'glsa-201412-17.xml') diff --git a/glsa-201412-17.xml b/glsa-201412-17.xml new file mode 100644 index 00000000..15715e98 --- /dev/null +++ b/glsa-201412-17.xml @@ -0,0 +1,64 @@ + + + + + + GPL Ghostscript: Multiple vulnerabilities + Multiple vulnerabilities have been found in GPL Ghostscript, the + worst of which may allow execution of arbitrary code. + + ghostscript-gpl + December 13, 2014 + December 13, 2014: 1 + 264594 + 300192 + 332061 + 437654 + remote + + + 9.10-r2 + 9.10-r2 + + + +

Ghostscript is an interpreter for the PostScript language and for PDF.

+
+ +

Multiple vulnerabilities have been discovered in GPL Ghostscript. Please + review the CVE identifiers referenced below for details. +

+
+ +

A context-dependent attacker could entice a user to open a specially + crafted PostScript file or PDF using GPL Ghostscript, possibly resulting + in execution of arbitrary code with the privileges of the process or a + Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All GPL Ghostscript users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose + ">=app-text/ghostscript-gpl-9.10-r2" + +
+ + CVE-2009-0196 + CVE-2009-0792 + CVE-2009-3743 + CVE-2009-4270 + CVE-2009-4897 + CVE-2010-1628 + CVE-2010-2055 + CVE-2010-4054 + CVE-2012-4405 + + a3li + ackle +
-- cgit v1.2.3-65-gdbad