ALINUX2-SA-2019%3A0003
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2018-16540: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact. CVE-2018-19475: psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same. CVE-2018-19476: psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion. CVE-2018-19477: psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion. CVE-2019-6116: In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | ghostscript |
Timeline
- Feb 20, 2019 CVE Updated
- Feb 21, 2019 CVE Published
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16540 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19476 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19477 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6116 advisory
- ALINUX2-SA-2019:0003: ghostscript security and bug fix update (Important) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19475 advisory