[ubuntu/focal-security] ghostscript 9.50~dfsg-5ubuntu4.3 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Fri Sep 10 11:54:27 UTC 2021
ghostscript (9.50~dfsg-5ubuntu4.3) focal-security; urgency=medium
* SECURITY UPDATE: Trivial -dSAFER bypass
- debian/patches/CVE-2021-3781-pre1.patch: handle format strings in
pipe OutputFiles in base/gslibctx.c.
- debian/patches/CVE-2021-3781-pre2.patch: fix pdfwrite "%d" mode with
file permissions in base/gsdevice.c, base/gslibctx.c.
- debian/patches/CVE-2021-3781-pre3.patch: move "break" to correct
place in base/gslibctx.c.
- debian/patches/CVE-2021-3781.patch: include device specifier strings
in access validation in base/gdevpipe.c, base/gp_mshdl.c,
base/gp_msprn.c, base/gp_os2pr.c, base/gslibctx.c.
- CVE-2021-3781
Date: 2021-09-09 14:37:11.994749+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.3
-------------- next part --------------
Sorry, changesfile not available.
More information about the Focal-changes
mailing list