Ghostscript is an interpreter for PostScript™ and Portable Document Format (PDF) files. Ghostscript consists of a PostScript interpreter layer, and a graphics library.
Security Fix(es):
An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.(CVE-2023-52722)
An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.(CVE-2024-33869)
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.(CVE-2024-33870)
{ "severity": "Medium" }
{ "src": [ "ghostscript-9.55.0-11.oe2203sp3.src.rpm" ], "x86_64": [ "ghostscript-9.55.0-11.oe2203sp3.x86_64.rpm", "ghostscript-debuginfo-9.55.0-11.oe2203sp3.x86_64.rpm", "ghostscript-debugsource-9.55.0-11.oe2203sp3.x86_64.rpm", "ghostscript-devel-9.55.0-11.oe2203sp3.x86_64.rpm", "ghostscript-tools-dvipdf-9.55.0-11.oe2203sp3.x86_64.rpm" ], "aarch64": [ "ghostscript-9.55.0-11.oe2203sp3.aarch64.rpm", "ghostscript-debuginfo-9.55.0-11.oe2203sp3.aarch64.rpm", "ghostscript-debugsource-9.55.0-11.oe2203sp3.aarch64.rpm", "ghostscript-devel-9.55.0-11.oe2203sp3.aarch64.rpm", "ghostscript-tools-dvipdf-9.55.0-11.oe2203sp3.aarch64.rpm" ], "noarch": [ "ghostscript-help-9.55.0-11.oe2203sp3.noarch.rpm" ] }