USN-3866-2: Ghostscript regression

Publication date

21 February 2019

Overview

USN-3866-1 introduced a regression in Ghostscript.


Packages

Details

USN-3866-1 fixed vulnerabilities in Ghostscript. The new Ghostscript
version introduced a regression when printing certain page sizes. This
update fixes the problem.

Original advisory details:

Tavis Ormandy discovered that Ghostscript incorrectly handled certain
PostScript files. If a user or automated system were tricked into
processing a specially crafted file, a remote attacker could possibly use
this issue to access arbitrary files, execute arbitrary code, or cause a
denial of service.

USN-3866-1 fixed vulnerabilities in Ghostscript. The new Ghostscript
version introduced a regression when printing certain page sizes. This
update fixes the problem.

Original advisory details:

Tavis Ormandy discovered that Ghostscript incorrectly handled certain
PostScript files. If a user or automated system were tricked into
processing a specially crafted file, a remote attacker could possibly use
this issue to access arbitrary files, execute arbitrary code, or cause a
denial of service.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:


Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›