FEDORA-2016-1c13825502

security update in Fedora 23 for ghostscript

Status: stable 2 years ago

This is a rebase of ghostscript package, to address several security issues:

  • CVE-2016-7977 - .libfile does not honor -dSAFER
  • CVE-2013-5653 - getenv and filenameforall ignore -dSAFER
  • CVE-2016-7976 - various userparams allow %pipe% in paths, allowing remote shell
  • CVE-2016-7978 - reference leak in .setdevice allows use-after-free and remote code
  • CVE-2016-7979 - Type confusion in .initialize_dsc_parser allows remote code execution

INFORMATION FOR FEDORA PACKAGERS & MAINTAINERS:

ghostscript has been rebased to latest upstream version (9.20). Rebase notes:

  • no API/ABI changes between versions 9.16 -> 9.20 according to upstream
  • OpenJPEG support has been retained
  • ijs-config custom tool from upstream has been removed (by upstream) (pkg-config is used by default now instead, see commit 0c176a9)
  • some patches were updated to 'git format-patch' format & renamed
  • rest of the patches were deleted (irrelevant for current version), mostly because upstream has fixed those issues in some way

Comments 5

This update has been submitted for testing by dkaspar.

This update has been pushed to testing.

This update has reached 7 days in testing and can be pushed to stable now if the maintainer wishes

This update has been submitted for stable by dkaspar.

This update has been pushed to stable.

Add Comment & Feedback

Please login to add feedback.

Content Type
RPM
Status
stable
Test Gating
Submitted by
Update Type
security
Update Severity
high
Karma
0
stable threshold: 12
unstable threshold: -4
Autopush (karma)
Enabled
Autopush (time)
Disabled
Dates
submitted 2 years ago
in testing 2 years ago
in stable 2 years ago

Related Bugs 5

00 #1380327 CVE-2013-5653 ghostscript: getenv and filenameforall ignore -dSAFER
00 #1380415 CVE-2016-7977 ghostscript: .libfile does not honor -dSAFER
00 #1382294 CVE-2016-7976 ghostscript: various userparams allow %pipe% in paths, allowing remote shell
00 #1382300 CVE-2016-7978 ghostscript: reference leak in .setdevice allows use-after-free and remote code execution
00 #1382305 CVE-2016-7979 ghostscript: Type confusion in .initialize_dsc_parser allows remote code execution

Automated Test Results