Updated ghostscript packages fix security vulnerability
Publication date: 05 Apr 2019Modification date: 05 Apr 2019
Type: security
Affected Mageia releases : 6
CVE: CVE-2019-3835 , CVE-2019-3838
Description
It was found that the superexec operator was available in the internal dictionary. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. (CVE-2019-3835) It was found that the forceput operator could be extracted from the DefineResource method using methods similar to the ones described in CVE-2019-6116. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constraints imposed by -dSAFER. (CVE-2019-3838)
References
SRPMS
6/core
- ghostscript-9.26-1.3.mga6