stable

ghostscript-9.20-2.fc25

FEDORA-2016-2df27a2224 created by dkaspar 9 years ago for Fedora 25

This is a rebase of ghostscript package, to address several security issues:

  • CVE-2016-7977 - .libfile does not honor -dSAFER
  • CVE-2013-5653 - getenv and filenameforall ignore -dSAFER
  • CVE-2016-7976 - various userparams allow %pipe% in paths, allowing remote shell
  • CVE-2016-7978 - reference leak in .setdevice allows use-after-free and remote code
  • CVE-2016-7979 - Type confusion in .initialize_dsc_parser allows remote code execution

INFORMATION FOR FEDORA PACKAGERS & MAINTAINERS:

ghostscript has been rebased to latest upstream version (9.20). Rebase notes:

  • no API/ABI changes between versions 9.16 -> 9.20 according to upstream
  • OpenJPEG support has been retained
  • ijs-config custom tool from upstream has been removed (by upstream) (pkg-config is used by default now instead, see commit 0c176a9)
  • some patches were updated to 'git format-patch' format & renamed
  • rest of the patches were deleted (irrelevant for current version), mostly because upstream has fixed those issues in some way

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2016-2df27a2224

This update has been submitted for testing by dkaspar.

9 years ago

This update has been pushed to testing.

9 years ago
User Icon besser82 commented & provided feedback 9 years ago
karma

Works fine! LGTM! =)

User Icon pwalter commented & provided feedback 9 years ago
karma

Works

User Icon lupinix commented & provided feedback 9 years ago
karma

works fine

User Icon akinsola commented & provided feedback 9 years ago
karma

worked

User Icon williamjmorenor commented & provided feedback 9 years ago
karma

Work for me

User Icon heikoada commented & provided feedback 9 years ago
karma

LGTM

User Icon cserpentis commented & provided feedback 9 years ago
karma

works for me

This update has reached 3 days in testing and can be pushed to stable now if the maintainer wishes

9 years ago
User Icon kuosmanen commented & provided feedback 9 years ago
karma

looks good

User Icon chr77 commented & provided feedback 9 years ago
karma

Works for me

User Icon kalev commented & provided feedback 9 years ago
karma

Works fine here

User Icon cairo provided feedback 9 years ago
karma

This update has been submitted for stable by bodhi.

9 years ago
User Icon smithp commented & provided feedback 9 years ago
karma

+1

This update has been pushed to stable.

9 years ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
12
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-4
Stable by Karma
12
Stable by Time
disabled
Dates
submitted
9 years ago
in testing
9 years ago
in stable
9 years ago
BZ#1380327 CVE-2013-5653 ghostscript: getenv and filenameforall ignore -dSAFER
0
0
BZ#1380415 CVE-2016-7977 ghostscript: .libfile does not honor -dSAFER
0
0
BZ#1382294 CVE-2016-7976 ghostscript: various userparams allow %pipe% in paths, allowing remote shell
0
0
BZ#1382300 CVE-2016-7978 ghostscript: reference leak in .setdevice allows use-after-free and remote code execution
0
0
BZ#1382305 CVE-2016-7979 ghostscript: Type confusion in .initialize_dsc_parser allows remote code execution
0
0

Automated Test Results