SciLinux: SLSA-2018-3834-1 Important: ghostscript on SL7.x x86_64
Summary
Important: ghostscript security and bug fix update
Security Fixes
* ghostscript: Incorrect free logic in pagedevice replacement (699664)
(CVE-2018-16541)
* ghostscript: Incorrect "restoration of privilege" checking when running
out of stack during exception handling (CVE-2018-16802)
* ghostscript: User-writable error exception table (CVE-2018-17183)
* ghostscript: Saved execution stacks can leak operator arrays (incomplete
fix for CVE-2018-17183) (CVE-2018-17961)
* ghostscript: Saved execution stacks can leak operator arrays
(CVE-2018-18073)
* ghostscript: 1Policy operator allows a sandbox protection bypass
(CVE-2018-18284)
* ghostscript: Type confusion in setpattern (700141) (CVE-2018-19134)
* ghostscript: Improperly implemented security check in zsetdevice
function in psi/zdevice.c (CVE-2018-19409)
* ghostscript: Uninitialized memory access in the aesdecode operator
(699665) (CVE-2018-15911)