From 9c38541fc770d5ef98f0327092ae33c0bab71167 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sun, 17 Sep 2023 05:24:21 +0000 Subject: [ GLSA 202309-03 ] GPL Ghostscript: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/904245 Bug: https://bugs.gentoo.org/910294 Signed-off-by: GLSAMaker Signed-off-by: Sam James --- glsa-202309-03.xml | 45 +++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 45 insertions(+) create mode 100644 glsa-202309-03.xml diff --git a/glsa-202309-03.xml b/glsa-202309-03.xml new file mode 100644 index 00000000..71c1f8f0 --- /dev/null +++ b/glsa-202309-03.xml @@ -0,0 +1,45 @@ + + + + GPL Ghostscript: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in GPL Ghostscript, the worst of which could result in remote code execution. + ghostscript-gpl + 2023-09-17 + 2023-09-17 + 904245 + 910294 + remote + + + 10.01.2 + 10.01.2 + + + +

Ghostscript is an interpreter for the PostScript language and for PDF.

+
+ +

Multiple vulnerabilities have been discovered in GPL Ghostscript. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All GPL Ghostscript users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-text/ghostscript-gpl-10.01.2" + +
+ + CVE-2022-2085 + CVE-2023-28879 + CVE-2023-36664 + + ajak + sam +
\ No newline at end of file -- cgit v1.2.3-65-gdbad