Updated ghostscript packages fix security vulnerabilities
Publication date: 12 Sep 2019Modification date: 12 Sep 2019
Type: security
Affected Mageia releases : 6 , 7
CVE: CVE-2019-14811 , CVE-2019-14812 , CVE-2019-14813
Description
The updated packages fix security vulnerabilities:
Safer Mode Bypass by .forceput Exposure in .pdf_hook_DSC_Creator.
(CVE-2019-14811)
Safer Mode Bypass by .forceput Exposure in setuserparams. (CVE-2019-14812)
Safer Mode Bypass by .forceput Exposure in setsystemparams. (CVE-2019-14813)
Safer Mode Bypass by .forceput Exposure in .pdfexectoken and other
procedures. (CVE-2019-14817)
References
SRPMS
6/core
- ghostscript-9.26-1.6.mga6
7/core
- ghostscript-9.27-1.3.mga7