[CLSA-2026:1787916987] Fix CVE(s): CVE-2024-33871, CVE-2024-46951, CVE-2024-46953, CVE-2024-46956
Type:
security
Severity:
Important
Release date:
2026-08-28 11:36:40 UTC
Description:
* SECURITY UPDATE: arbitrary code execution via the opvp Driver parameter - debian/patches/CVE-2024-33871.patch: refuse a Driver change once LockSafetyParams is set, and report the Driver length without the trailing NUL, in contrib/opvp/gdevopvp.c. - CVE-2024-33871 * SECURITY UPDATE: unchecked Implementation pointer in Pattern colour space - debian/patches/CVE-2024-46951.patch: check that the Pattern Implementation object really is a pattern instance before dereferencing it in patterncomponent() in psi/zcolor.c. - CVE-2024-46951 * SECURITY UPDATE: integer overflow validating the output filename format - debian/patches/CVE-2024-46953.patch: reject format widths that overflow an int and tighten the length check in gx_parse_output_format() and gx_parse_output_file_name() in base/gsdevice.c. - CVE-2024-46953 * SECURITY UPDATE: out-of-bounds data access in filenameforall - debian/patches/CVE-2024-46956.patch: correct the buffer length check in file_continue() in psi/zfile.c, so filenameforall cannot return a string whose declared size exceeds the scratch buffer. - CVE-2024-46956
Updated packages:
  • ghostscript_9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1_amd64.deb
    sha:8e8281a9dcff73bb689f0d7cdaadd22343d9db34
  • ghostscript-doc_9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1_all.deb
    sha:4a70b0bb281daed226c6362686752ec56b903dc8
  • ghostscript-x_9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1_amd64.deb
    sha:abe7c9171b2f7d9d7ba46459e59acdb3feb5e027
  • libgs-dev_9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1_amd64.deb
    sha:992fdc125bb4914816d799221a8b00a9462f000d
  • libgs9_9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1_amd64.deb
    sha:2cf2ca1e5473a7a600d7f4e2ba17618c7680da9d
  • libgs9-common_9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1_all.deb
    sha:20cef2c226d8226c2b91f77425e0c04fac259865
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.