Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5888-1] ghostscript security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5888-1] ghostscript security update


Chronologisch Thread  
  • From: Salvatore Bonaccorso <carnil AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5888-1] ghostscript security update
  • Date: Wed, 26 Mar 2025 19:41:31 +0000
  • Authentication-results: lists.piratenpartei.de; dkim=none; spf=none (lists.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
  • List-archive: https://lists.debian.org/msgid-search/E1txWd1-009qGF-4P AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version: Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=1sykQ+nbJt84dnAvQvJP5un+/b4jsRklzN3HKtR0rSo=; b=mj 46oIdAZWABkD0PEjjKxs9xuDlU40geZ5WWDX80wfj5Zy4lVeGL6sTayaBM2/gAlgu4IXMi4LRqzPl k4ZCGdCz9Zk+NMDowuYPaqnW3PadYQXTbC6Pq0KPJost0L6Xn7oUo9VHUfJofTk2H9hRBWb1FDCZ3 ZsUdAel5Dv8A2yuo4i3FVhmcj3CK7iYHjM+z9DmnejFYXRNEZXSyaiTYHymni8qPRFqktQ9xITP// wnQevbHkb7snlWUYVKaooIxUOtWsxtV6hxaQAfNE9nZZ96bSYO5VFr44BbXgfhl98k29Ijr27PMVo gnRvLTOQN+iDsDw07wxYGtwqaIG2RcfQ==;
  • Old-return-path: <carnil AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Wed, 26 Mar 2025 19:41:51 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <gRRgXkw6TkC.A.YCCL._hF5nB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5888-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
March 26, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : ghostscript
CVE ID : CVE-2025-27830 CVE-2025-27831 CVE-2025-27832 CVE-2025-27833
CVE-2025-27834 CVE-2025-27835 CVE-2025-27836

Multiple security issues were discovered in Ghostscript, the GPL
PostScript/PDF interpreter, which could result in denial of service and
potentially the execution of arbitrary code if malformed document files
are processed.

For the stable distribution (bookworm), these problems have been fixed in
version 10.0.0~dfsg-11+deb12u7.

We recommend that you upgrade your ghostscript packages.

For the detailed security status of ghostscript please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/ghostscript

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmfkWDlfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0S+xBAAgIAWEmQPFRkyUB5bOeD07UrC+5A64s1cjxx+1V6L8XV3TKWwTxSjYTeZ
hlM15Gt0tMvydL9oaKHHkHxA3tVee8pkxK5b/0wz4Zf+EBFjFfYuPjIIBOu9WNQz
zttqEyNP+KZMewWHOHFzDA/6mb5Px726TBLvUFyTVoPfJoPP4AVfHCDClozpp9K4
pa9jXPlE+2L41RFgD73NZWPiw9UQwfF4ocMbFlOv7QUqG80zqvBPntljqcR7APL+
auAHzLcbELLRBIoPmPuAQgJFgpKoLnRLjJDaq9FvvD+cl8+uTN2PS0AVmSzViZzP
dVg4T8owa/zRYPy7P+rt1c/kTl0QT9mPbzaZ6AHuI6K0P11fi5Qm9Kid+i2vRKx8
9BIcBAnNaZtiCi3p4wqo32M4Qa4ocRo/UF3uHuDYEWqZ8PTgHBgfRgiz9mjqXEmV
CCW6rh292VjusJ2RyJ+GqrxrdHby4658gj+uNI148/A596+UhYmxN5YiDtqcSLLk
6uXe260UJe+bvbZcuL1CMgceWbxfoYIMze236vtyglYQcfdW/09o9hdvGKI7GIxV
YukIqo3eoEEd4o5aKDaQQv9I+D0KICzb2US/6Yp7InP2pgDTiqPdZFfROQ3uPfl/
+Jk0+HFWd2mhQplNiSijBiToWS5x6KcRNi2/l29JgtKgqsmKJM8=
=SIUy
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5888-1] ghostscript security update, Salvatore Bonaccorso, 26.03.2025

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang