• Ghostscript vulnerabilities

    From bugz_ubuntu@21:4/110 to Ubuntu Users on Monday, August 24, 2020 16:10:01
    ghostscript vulnerabilities

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 20.04 LTS
    * Ubuntu 18.04 LTS
    * Ubuntu 16.04 LTS

    Summary

    Several security issues were fixed in Ghostscript.

    Software Description

    * ghostscript - PostScript and PDF interpreter

    Details

    It was discovered that Ghostscript incorrectly handled certain
    document files. If a user or automated system were tricked into
    processing a specially crafted file, a remote attacker could use
    this issue to cause Ghostscript to crash, resulting in a denial of
    service, or possibly execute arbitrary code.

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 20.04 LTS
    ghostscript - 9.50~dfsg-5ubuntu4.2
    libgs9 - 9.50~dfsg-5ubuntu4.2

    Ubuntu 18.04 LTS
    ghostscript - 9.26~dfsg+0-0ubuntu0.18.04.13
    libgs9 - 9.26~dfsg+0-0ubuntu0.18.04.13

    Ubuntu 16.04 LTS
    ghostscript - 9.26~dfsg+0-0ubuntu0.16.04.13
    libgs9 - 9.26~dfsg+0-0ubuntu0.16.04.13

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    In general, a standard system update will make all the necessary
    changes.

    References

    * CVE-2020-16287
    * CVE-2020-16288
    * CVE-2020-16289
    * CVE-2020-16290
    * CVE-2020-16291
    * CVE-2020-16292
    * CVE-2020-16293
    * CVE-2020-16294
    * CVE-2020-16295
    * CVE-2020-16296
    * CVE-2020-16297
    * CVE-2020-16298
    * CVE-2020-16299
    * CVE-2020-16300
    * CVE-2020-16301
    * CVE-2020-16302
    * CVE-2020-16303
    * CVE-2020-16304
    * CVE-2020-16305
    * CVE-2020-16306
    * CVE-2020-16307
    * CVE-2020-16308
    * CVE-2020-16309
    * CVE-2020-16310
    * CVE-2020-17538

    --- Mystic BBS v1.12 A45 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)