GPL Ghostscript: Multiple vulnerabilities
Multiple vulnerabilities have been found in GPL Ghostscript, the
worst of which could result in the execution of arbitrary code.
ghostscript
2018-11-24
2018-11-24
618820
626418
635426
655404
668846
671732
remote
9.26
9.26
Ghostscript is an interpreter for the PostScript language and for PDF.
Multiple vulnerabilities have been discovered in GPL Ghostscript. Please
review the CVE identifiers referenced below for additional information.
A context-dependent attacker could entice a user to open a specially
crafted PostScript file or PDF document using GPL Ghostscript possibly
resulting in the execution of arbitrary code with the privileges of the
process, a Denial of Service condition, or other unspecified impacts,
There is no known workaround at this time.
All GPL Ghostscript users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-text/ghostscript-gpl-9.26"
CVE-2017-11714
CVE-2017-7948
CVE-2017-9610
CVE-2017-9611
CVE-2017-9612
CVE-2017-9618
CVE-2017-9619
CVE-2017-9620
CVE-2017-9726
CVE-2017-9727
CVE-2017-9739
CVE-2017-9740
CVE-2017-9835
CVE-2018-10194
CVE-2018-15908
CVE-2018-15909
CVE-2018-15910
CVE-2018-15911
CVE-2018-16509
CVE-2018-16510
CVE-2018-16511
CVE-2018-16513
CVE-2018-16539
CVE-2018-16540
CVE-2018-16541
CVE-2018-16542
CVE-2018-16543
CVE-2018-16585
CVE-2018-16802
CVE-2018-18284
CVE-2018-19409
b-man
b-man