ELA-1243-1 ghostscript security update

multiple vulnerabilities

2024-11-24
Packageghostscript
Version9.26a~dfsg-0+deb8u13 (jessie), 9.26a~dfsg-0+deb9u13 (stretch), 9.27~dfsg-2+deb10u10 (buster)
Related CVEs CVE-2024-46951 CVE-2024-46953 CVE-2024-46955 CVE-2024-46956


Multiple vulnerabilities have been fixed in the PostScript/PDF interpreter Ghostscript.

CVE-2024-46951

PS interpreter unchecked pointer

CVE-2024-46953

output filename format string integer overflow

CVE-2024-46955

PS interpreter out-of-bounds

CVE-2024-46956

PS interpreter out-of-bounds


For Debian 10 buster, these problems have been fixed in version 9.27~dfsg-2+deb10u10.

For Debian 8 jessie, these problems have been fixed in version 9.26a~dfsg-0+deb8u13.

For Debian 9 stretch, these problems have been fixed in version 9.26a~dfsg-0+deb9u13.

We recommend that you upgrade your ghostscript packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.