Release date:
2026-08-28 11:36:40 UTC
Description:
* SECURITY UPDATE: arbitrary code execution via the opvp Driver parameter
- debian/patches/CVE-2024-33871.patch: refuse a Driver change once
LockSafetyParams is set, and report the Driver length without the
trailing NUL, in contrib/opvp/gdevopvp.c.
- CVE-2024-33871
* SECURITY UPDATE: unchecked Implementation pointer in Pattern colour space
- debian/patches/CVE-2024-46951.patch: check that the Pattern
Implementation object really is a pattern instance before dereferencing
it in patterncomponent() in psi/zcolor.c.
- CVE-2024-46951
* SECURITY UPDATE: integer overflow validating the output filename format
- debian/patches/CVE-2024-46953.patch: reject format widths that overflow
an int and tighten the length check in gx_parse_output_format() and
gx_parse_output_file_name() in base/gsdevice.c.
- CVE-2024-46953
* SECURITY UPDATE: out-of-bounds data access in filenameforall
- debian/patches/CVE-2024-46956.patch: correct the buffer length check in
file_continue() in psi/zfile.c, so filenameforall cannot return a string
whose declared size exceeds the scratch buffer.
- CVE-2024-46956
Updated packages:
-
ghostscript_9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1_amd64.deb
sha:8e8281a9dcff73bb689f0d7cdaadd22343d9db34
-
ghostscript-doc_9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1_all.deb
sha:4a70b0bb281daed226c6362686752ec56b903dc8
-
ghostscript-x_9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1_amd64.deb
sha:abe7c9171b2f7d9d7ba46459e59acdb3feb5e027
-
libgs-dev_9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1_amd64.deb
sha:992fdc125bb4914816d799221a8b00a9462f000d
-
libgs9_9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1_amd64.deb
sha:2cf2ca1e5473a7a600d7f4e2ba17618c7680da9d
-
libgs9-common_9.26~dfsg+0-0ubuntu0.18.04.18+tuxcare.els1_all.deb
sha:20cef2c226d8226c2b91f77425e0c04fac259865
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.