{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* SECURITY UPDATE: arbitrary code execution via the opvp Driver parameter\n     - debian/patches/CVE-2024-33871.patch: refuse a Driver change once\n       LockSafetyParams is set, and report the Driver length without the\n       trailing NUL, in contrib/opvp/gdevopvp.c.\n     - CVE-2024-33871\n   * SECURITY UPDATE: unchecked Implementation pointer in Pattern colour space\n     - debian/patches/CVE-2024-46951.patch: check that the Pattern\n       Implementation object really is a pattern instance before dereferencing\n       it in patterncomponent() in psi/zcolor.c.\n     - CVE-2024-46951\n   * SECURITY UPDATE: integer overflow validating the output filename format\n     - debian/patches/CVE-2024-46953.patch: reject format widths that overflow\n       an int and tighten the length check in gx_parse_output_format() and\n       gx_parse_output_file_name() in base/gsdevice.c.\n     - CVE-2024-46953\n   * SECURITY UPDATE: out-of-bounds data access in filenameforall\n     - debian/patches/CVE-2024-46956.patch: correct the buffer length check in\n       file_continue() in psi/zfile.c, so filenameforall cannot return a string\n       whose declared size exceeds the scratch buffer.\n     - CVE-2024-46956",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787916987",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787916987"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu18.04els/advisories/2026/clsa-2026_1787916987.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-28T11:37:27Z",
      "generator": {
        "date": "2026-08-28T11:37:27Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1787916987",
      "initial_release_date": "2026-08-28T11:37:27Z",
      "revision_history": [
        {
          "date": "2026-08-28T11:37:27Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "Fix CVE(s): CVE-2024-33871, CVE-2024-46951, CVE-2024-46953, CVE-2024-46956"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 18.04",
                "product": {
                  "name": "Ubuntu 18.04",
                  "product_id": "Ubuntu-18",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "ghostscript-doc-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
                "product": {
                  "name": "ghostscript-doc-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
                  "product_id": "ghostscript-doc-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/ghostscript-doc@9.26~dfsg%2B0-0ubuntu0.18.04.18%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libgs9-common-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
                "product": {
                  "name": "libgs9-common-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
                  "product_id": "libgs9-common-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libgs9-common@9.26~dfsg%2B0-0ubuntu0.18.04.18%2Btuxcare.els1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "ghostscript-x-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
                "product": {
                  "name": "ghostscript-x-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
                  "product_id": "ghostscript-x-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/ghostscript-x@9.26~dfsg%2B0-0ubuntu0.18.04.18%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libgs9-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
                "product": {
                  "name": "libgs9-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
                  "product_id": "libgs9-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libgs9@9.26~dfsg%2B0-0ubuntu0.18.04.18%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "ghostscript-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
                "product": {
                  "name": "ghostscript-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
                  "product_id": "ghostscript-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/ghostscript@9.26~dfsg%2B0-0ubuntu0.18.04.18%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libgs-dev-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
                "product": {
                  "name": "libgs-dev-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
                  "product_id": "libgs-dev-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libgs-dev@9.26~dfsg%2B0-0ubuntu0.18.04.18%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ghostscript-doc-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:ghostscript-doc-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all"
        },
        "product_reference": "ghostscript-doc-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libgs9-common-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libgs9-common-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all"
        },
        "product_reference": "libgs9-common-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ghostscript-x-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:ghostscript-x-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64"
        },
        "product_reference": "ghostscript-x-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libgs9-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libgs9-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64"
        },
        "product_reference": "libgs9-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ghostscript-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:ghostscript-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64"
        },
        "product_reference": "ghostscript-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libgs-dev-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libgs-dev-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64"
        },
        "product_reference": "libgs-dev-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2024-46953",
      "cwe": {
        "id": "CWE-190",
        "name": "Integer Overflow or Wraparound"
      },
      "notes": [
        {
          "category": "description",
          "text": "An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-18:ghostscript-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:ghostscript-doc-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
          "Ubuntu-18:ghostscript-x-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:libgs-dev-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:libgs9-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:libgs9-common-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-46953"
        },
        {
          "category": "external",
          "summary": "https://bugs.ghostscript.com/show_bug.cgi?id=707793",
          "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707793"
        },
        {
          "category": "external",
          "summary": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=1f21a45df0fa3abec4cff12951022b192dda3c00",
          "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=1f21a45df0fa3abec4cff12951022b192dda3c00"
        },
        {
          "category": "external",
          "summary": "https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html",
          "url": "https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html"
        },
        {
          "category": "external",
          "summary": "https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/",
          "url": "https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/11/msg00023.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00023.html"
        }
      ],
      "release_date": "2024-11-10T22:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-28T11:36:28.975789Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787916987",
          "product_ids": [
            "Ubuntu-18:ghostscript-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:ghostscript-doc-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
            "Ubuntu-18:ghostscript-x-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:libgs-dev-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:libgs9-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:libgs9-common-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787916987"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-46951",
      "cwe": {
        "id": "CWE-824",
        "name": "Access of Uninitialized Pointer"
      },
      "notes": [
        {
          "category": "description",
          "text": "An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-18:ghostscript-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:ghostscript-doc-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
          "Ubuntu-18:ghostscript-x-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:libgs-dev-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:libgs9-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:libgs9-common-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-46951"
        },
        {
          "category": "external",
          "summary": "https://bugs.ghostscript.com/show_bug.cgi?id=707991",
          "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707991"
        },
        {
          "category": "external",
          "summary": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f49812186baa7d1362880673408a6fbe8719b4f8",
          "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f49812186baa7d1362880673408a6fbe8719b4f8"
        },
        {
          "category": "external",
          "summary": "https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html",
          "url": "https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html"
        },
        {
          "category": "external",
          "summary": "https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/",
          "url": "https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/11/msg00023.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00023.html"
        }
      ],
      "release_date": "2024-11-10T21:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-28T11:36:28.975789Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787916987",
          "product_ids": [
            "Ubuntu-18:ghostscript-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:ghostscript-doc-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
            "Ubuntu-18:ghostscript-x-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:libgs-dev-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:libgs9-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:libgs9-common-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787916987"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-33871",
      "cwe": {
        "id": "CWE-94",
        "name": "Improper Control of Generation of Code ('Code Injection')"
      },
      "notes": [
        {
          "category": "description",
          "text": "An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-18:ghostscript-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:ghostscript-doc-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
          "Ubuntu-18:ghostscript-x-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:libgs-dev-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:libgs9-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:libgs9-common-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-33871"
        },
        {
          "category": "external",
          "summary": "https://bugs.ghostscript.com/show_bug.cgi?id=707754",
          "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707754"
        },
        {
          "category": "external",
          "summary": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=7145885041bb52cc23964f0aa2aec1b1c82b5908",
          "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=7145885041bb52cc23964f0aa2aec1b1c82b5908"
        },
        {
          "category": "external",
          "summary": "https://www.openwall.com/lists/oss-security/2024/06/28/2",
          "url": "https://www.openwall.com/lists/oss-security/2024/06/28/2"
        }
      ],
      "release_date": "2024-07-03T19:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-28T11:36:28.975789Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787916987",
          "product_ids": [
            "Ubuntu-18:ghostscript-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:ghostscript-doc-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
            "Ubuntu-18:ghostscript-x-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:libgs-dev-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:libgs9-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:libgs9-common-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787916987"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-46956",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "notes": [
        {
          "category": "description",
          "text": "An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-18:ghostscript-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:ghostscript-doc-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
          "Ubuntu-18:ghostscript-x-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:libgs-dev-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:libgs9-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
          "Ubuntu-18:libgs9-common-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-46956"
        },
        {
          "category": "external",
          "summary": "https://bugs.ghostscript.com/show_bug.cgi?id=707895",
          "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707895"
        },
        {
          "category": "external",
          "summary": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f4151f12db32cd3ed26c24327de714bf2c3ed6ca",
          "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f4151f12db32cd3ed26c24327de714bf2c3ed6ca"
        },
        {
          "category": "external",
          "summary": "https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html",
          "url": "https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html"
        },
        {
          "category": "external",
          "summary": "https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/",
          "url": "https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/11/msg00023.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00023.html"
        }
      ],
      "release_date": "2024-11-10T22:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-28T11:36:28.975789Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787916987",
          "product_ids": [
            "Ubuntu-18:ghostscript-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:ghostscript-doc-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all",
            "Ubuntu-18:ghostscript-x-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:libgs-dev-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:libgs9-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.amd64",
            "Ubuntu-18:libgs9-common-0:9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1.all"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787916987"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}