- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3965-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                          Adrian Bunk
November 24, 2024                             https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : ghostscript
Version        : 9.53.3~dfsg-7+deb11u9
CVE ID         : CVE-2024-46951 CVE-2024-46953 CVE-2024-46955 CVE-2024-46956

Multiple vulnerabilities have been fixed in the PostScript/PDF 
interpreter Ghostscript.

CVE-2024-46951

    PS interpreter unchecked pointer

CVE-2024-46953

    output filename format string integer overflow

CVE-2024-46955

    PS interpreter out-of-bounds

CVE-2024-46956

    PS interpreter out-of-bounds

For Debian 11 bullseye, these problems have been fixed in version
9.53.3~dfsg-7+deb11u9.

We recommend that you upgrade your ghostscript packages.

For the detailed security status of ghostscript please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ghostscript

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-3965-1: ghostscript Security Advisory Updates

November 24, 2024
Multiple vulnerabilities have been fixed in the PostScript/PDF interpreter Ghostscript

Summary

CVE-2024-46951

PS interpreter unchecked pointer

CVE-2024-46953

output filename format string integer overflow

CVE-2024-46955

PS interpreter out-of-bounds

CVE-2024-46956

PS interpreter out-of-bounds

For Debian 11 bullseye, these problems have been fixed in version
9.53.3~dfsg-7+deb11u9.

We recommend that you upgrade your ghostscript packages.

For the detailed security status of ghostscript please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ghostscript

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : ghostscript
Version : 9.53.3~dfsg-7+deb11u9
CVE ID : CVE-2024-46951 CVE-2024-46953 CVE-2024-46955 CVE-2024-46956

Related News