"-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
=====================================================================
Red Hat Security Advisory
Synopsis: Moderate: ghostscript security update
Advisory ID: RHSA-2009:0345-01
Product: Red Hat Enterprise Linux
Advisory URL: https://rhn.redhat.com/errata/RHSA-2009-0345.html
Issue date: 2009-03-19
CVE Names: CVE-2009-0583 CVE-2009-0584
=====================================================================
1. Summary:
Updated ghostscript packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 3, 4, and 5.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
2. Relevant releases/architectures:
RHEL Desktop Workstation (v. 5 client) - i386, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64
Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64
3. Description:
Ghostscript is a set of software that provides a PostScript(TM)
interpreter, a set of C procedures (the Ghostscript library, which
implements the graphics capabilities in the PostScript language) and
an interpreter for Portable Document Format (PDF) files.
Multiple integer overflow flaws which could lead to heap-based buffer
overflows, as well as multiple insufficient input validation flaws, were
found in Ghostscript's International Color Consortium Format library
(icclib). Using specially-crafted ICC profiles, an attacker could create a
malicious PostScript or PDF file with embedded images which could cause
Ghostscript to crash, or, potentially, execute arbitrary code when opened
by the victim. (CVE-2009-0583, CVE-2009-0584)
All users of ghostscript are advised to upgrade to these updated packages,
which contain a backported patch to correct these issues.
4. Solution:
Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.
This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259
5. Bugs fixed (http://bugzilla.redhat.com/):
487742 - CVE-2009-0583 ghostscript: Multiple integer overflows in the International Color Consortium Format Library
487744 - CVE-2009-0584 ghostscript: Multiple insufficient upper-bounds checks on certain sizes in the International Color Consortium Format Library
6. Package List:
Red Hat Enterprise Linux AS version 3:
Source:
ftp://updates.redhat.com/enterprise/3AS/en/os/SRPMS/ghostscript-7.05-32.1.17.src.rpm
i386:
ghostscript-7.05-32.1.17.i386.rpm
ghostscript-debuginfo-7.05-32.1.17.i386.rpm
ghostscript-devel-7.05-32.1.17.i386.rpm
hpijs-1.3-32.1.17.i386.rpm
ia64:
ghostscript-7.05-32.1.17.i386.rpm
ghostscript-7.05-32.1.17.ia64.rpm
ghostscript-debuginfo-7.05-32.1.17.i386.rpm
ghostscript-debuginfo-7.05-32.1.17.ia64.rpm
ghostscript-devel-7.05-32.1.17.ia64.rpm
hpijs-1.3-32.1.17.ia64.rpm
ppc:
ghostscript-7.05-32.1.17.ppc.rpm
ghostscript-7.05-32.1.17.ppc64.rpm
ghostscript-debuginfo-7.05-32.1.17.ppc.rpm
ghostscript-debuginfo-7.05-32.1.17.ppc64.rpm
ghostscript-devel-7.05-32.1.17.ppc.rpm
hpijs-1.3-32.1.17.ppc.rpm
s390:
ghostscript-7.05-32.1.17.s390.rpm
ghostscript-debuginfo-7.05-32.1.17.s390.rpm
ghostscript-devel-7.05-32.1.17.s390.rpm
hpijs-1.3-32.1.17.s390.rpm
s390x:
ghostscript-7.05-32.1.17.s390.rpm
ghostscript-7.05-32.1.17.s390x.rpm
ghostscript-debuginfo-7.05-32.1.17.s390.rpm
ghostscript-debuginfo-7.05-32.1.17.s390x.rpm
ghostscript-devel-7.05-32.1.17.s390x.rpm
hpijs-1.3-32.1.17.s390x.rpm
x86_64:
ghostscript-7.05-32.1.17.i386.rpm
ghostscript-7.05-32.1.17.x86_64.rpm
ghostscript-debuginfo-7.05-32.1.17.i386.rpm
ghostscript-debuginfo-7.05-32.1.17.x86_64.rpm
ghostscript-devel-7.05-32.1.17.x86_64.rpm
hpijs-1.3-32.1.17.x86_64.rpm
Red Hat Desktop version 3:
Source:
ftp://updates.redhat.com/enterprise/3desktop/en/os/SRPMS/ghostscript-7.05-32.1.17.src.rpm
i386:
ghostscript-7.05-32.1.17.i386.rpm
ghostscript-debuginfo-7.05-32.1.17.i386.rpm
ghostscript-devel-7.05-32.1.17.i386.rpm
hpijs-1.3-32.1.17.i386.rpm
x86_64:
ghostscript-7.05-32.1.17.i386.rpm
ghostscript-7.05-32.1.17.x86_64.rpm
ghostscript-debuginfo-7.05-32.1.17.i386.rpm
ghostscript-debuginfo-7.05-32.1.17.x86_64.rpm
ghostscript-devel-7.05-32.1.17.x86_64.rpm
hpijs-1.3-32.1.17.x86_64.rpm
Red Hat Enterprise Linux ES version 3:
Source:
ftp://updates.redhat.com/enterprise/3ES/en/os/SRPMS/ghostscript-7.05-32.1.17.src.rpm
i386:
ghostscript-7.05-32.1.17.i386.rpm
ghostscript-debuginfo-7.05-32.1.17.i386.rpm
ghostscript-devel-7.05-32.1.17.i386.rpm
hpijs-1.3-32.1.17.i386.rpm
ia64:
ghostscript-7.05-32.1.17.i386.rpm
ghostscript-7.05-32.1.17.ia64.rpm
ghostscript-debuginfo-7.05-32.1.17.i386.rpm
ghostscript-debuginfo-7.05-32.1.17.ia64.rpm
ghostscript-devel-7.05-32.1.17.ia64.rpm
hpijs-1.3-32.1.17.ia64.rpm
x86_64:
ghostscript-7.05-32.1.17.i386.rpm
ghostscript-7.05-32.1.17.x86_64.rpm
ghostscript-debuginfo-7.05-32.1.17.i386.rpm
ghostscript-debuginfo-7.05-32.1.17.x86_64.rpm
ghostscript-devel-7.05-32.1.17.x86_64.rpm
hpijs-1.3-32.1.17.x86_64.rpm
Red Hat Enterprise Linux WS version 3:
Source:
ftp://updates.redhat.com/enterprise/3WS/en/os/SRPMS/ghostscript-7.05-32.1.17.src.rpm
i386:
ghostscript-7.05-32.1.17.i386.rpm
ghostscript-debuginfo-7.05-32.1.17.i386.rpm
ghostscript-devel-7.05-32.1.17.i386.rpm
hpijs-1.3-32.1.17.i386.rpm
ia64:
ghostscript-7.05-32.1.17.i386.rpm
ghostscript-7.05-32.1.17.ia64.rpm
ghostscript-debuginfo-7.05-32.1.17.i386.rpm
ghostscript-debuginfo-7.05-32.1.17.ia64.rpm
ghostscript-devel-7.05-32.1.17.ia64.rpm
hpijs-1.3-32.1.17.ia64.rpm
x86_64:
ghostscript-7.05-32.1.17.i386.rpm
ghostscript-7.05-32.1.17.x86_64.rpm
ghostscript-debuginfo-7.05-32.1.17.i386.rpm
ghostscript-debuginfo-7.05-32.1.17.x86_64.rpm
ghostscript-devel-7.05-32.1.17.x86_64.rpm
hpijs-1.3-32.1.17.x86_64.rpm
Red Hat Enterprise Linux AS version 4:
Source:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/ghostscript-7.07-33.2.el4_7.5.src.rpm
i386:
ghostscript-7.07-33.2.el4_7.5.i386.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.i386.rpm
ghostscript-devel-7.07-33.2.el4_7.5.i386.rpm
ghostscript-gtk-7.07-33.2.el4_7.5.i386.rpm
ia64:
ghostscript-7.07-33.2.el4_7.5.i386.rpm
ghostscript-7.07-33.2.el4_7.5.ia64.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.i386.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.ia64.rpm
ghostscript-devel-7.07-33.2.el4_7.5.ia64.rpm
ghostscript-gtk-7.07-33.2.el4_7.5.ia64.rpm
ppc:
ghostscript-7.07-33.2.el4_7.5.ppc.rpm
ghostscript-7.07-33.2.el4_7.5.ppc64.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.ppc.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.ppc64.rpm
ghostscript-devel-7.07-33.2.el4_7.5.ppc.rpm
ghostscript-gtk-7.07-33.2.el4_7.5.ppc.rpm
s390:
ghostscript-7.07-33.2.el4_7.5.s390.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.s390.rpm
ghostscript-devel-7.07-33.2.el4_7.5.s390.rpm
ghostscript-gtk-7.07-33.2.el4_7.5.s390.rpm
s390x:
ghostscript-7.07-33.2.el4_7.5.s390.rpm
ghostscript-7.07-33.2.el4_7.5.s390x.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.s390.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.s390x.rpm
ghostscript-devel-7.07-33.2.el4_7.5.s390x.rpm
ghostscript-gtk-7.07-33.2.el4_7.5.s390x.rpm
x86_64:
ghostscript-7.07-33.2.el4_7.5.i386.rpm
ghostscript-7.07-33.2.el4_7.5.x86_64.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.i386.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.x86_64.rpm
ghostscript-devel-7.07-33.2.el4_7.5.x86_64.rpm
ghostscript-gtk-7.07-33.2.el4_7.5.x86_64.rpm
Red Hat Enterprise Linux Desktop version 4:
Source:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/ghostscript-7.07-33.2.el4_7.5.src.rpm
i386:
ghostscript-7.07-33.2.el4_7.5.i386.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.i386.rpm
ghostscript-devel-7.07-33.2.el4_7.5.i386.rpm
ghostscript-gtk-7.07-33.2.el4_7.5.i386.rpm
x86_64:
ghostscript-7.07-33.2.el4_7.5.i386.rpm
ghostscript-7.07-33.2.el4_7.5.x86_64.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.i386.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.x86_64.rpm
ghostscript-devel-7.07-33.2.el4_7.5.x86_64.rpm
ghostscript-gtk-7.07-33.2.el4_7.5.x86_64.rpm
Red Hat Enterprise Linux ES version 4:
Source:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/ghostscript-7.07-33.2.el4_7.5.src.rpm
i386:
ghostscript-7.07-33.2.el4_7.5.i386.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.i386.rpm
ghostscript-devel-7.07-33.2.el4_7.5.i386.rpm
ghostscript-gtk-7.07-33.2.el4_7.5.i386.rpm
ia64:
ghostscript-7.07-33.2.el4_7.5.i386.rpm
ghostscript-7.07-33.2.el4_7.5.ia64.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.i386.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.ia64.rpm
ghostscript-devel-7.07-33.2.el4_7.5.ia64.rpm
ghostscript-gtk-7.07-33.2.el4_7.5.ia64.rpm
x86_64:
ghostscript-7.07-33.2.el4_7.5.i386.rpm
ghostscript-7.07-33.2.el4_7.5.x86_64.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.i386.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.x86_64.rpm
ghostscript-devel-7.07-33.2.el4_7.5.x86_64.rpm
ghostscript-gtk-7.07-33.2.el4_7.5.x86_64.rpm
Red Hat Enterprise Linux WS version 4:
Source:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/ghostscript-7.07-33.2.el4_7.5.src.rpm
i386:
ghostscript-7.07-33.2.el4_7.5.i386.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.i386.rpm
ghostscript-devel-7.07-33.2.el4_7.5.i386.rpm
ghostscript-gtk-7.07-33.2.el4_7.5.i386.rpm
ia64:
ghostscript-7.07-33.2.el4_7.5.i386.rpm
ghostscript-7.07-33.2.el4_7.5.ia64.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.i386.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.ia64.rpm
ghostscript-devel-7.07-33.2.el4_7.5.ia64.rpm
ghostscript-gtk-7.07-33.2.el4_7.5.ia64.rpm
x86_64:
ghostscript-7.07-33.2.el4_7.5.i386.rpm
ghostscript-7.07-33.2.el4_7.5.x86_64.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.i386.rpm
ghostscript-debuginfo-7.07-33.2.el4_7.5.x86_64.rpm
ghostscript-devel-7.07-33.2.el4_7.5.x86_64.rpm
ghostscript-gtk-7.07-33.2.el4_7.5.x86_64.rpm
Red Hat Enterprise Linux Desktop (v. 5 client):
Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/ghostscript-8.15.2-9.4.el5_3.4.src.rpm
i386:
ghostscript-8.15.2-9.4.el5_3.4.i386.rpm
ghostscript-debuginfo-8.15.2-9.4.el5_3.4.i386.rpm
ghostscript-gtk-8.15.2-9.4.el5_3.4.i386.rpm
x86_64:
ghostscript-8.15.2-9.4.el5_3.4.i386.rpm
ghostscript-8.15.2-9.4.el5_3.4.x86_64.rpm
ghostscript-debuginfo-8.15.2-9.4.el5_3.4.i386.rpm
ghostscript-debuginfo-8.15.2-9.4.el5_3.4.x86_64.rpm
ghostscript-gtk-8.15.2-9.4.el5_3.4.x86_64.rpm
RHEL Desktop Workstation (v. 5 client):
Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/ghostscript-8.15.2-9.4.el5_3.4.src.rpm
i386:
ghostscript-debuginfo-8.15.2-9.4.el5_3.4.i386.rpm
ghostscript-devel-8.15.2-9.4.el5_3.4.i386.rpm
x86_64:
ghostscript-debuginfo-8.15.2-9.4.el5_3.4.i386.rpm
ghostscript-debuginfo-8.15.2-9.4.el5_3.4.x86_64.rpm
ghostscript-devel-8.15.2-9.4.el5_3.4.i386.rpm
ghostscript-devel-8.15.2-9.4.el5_3.4.x86_64.rpm
Red Hat Enterprise Linux (v. 5 server):
Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Server/en/os/SRPMS/ghostscript-8.15.2-9.4.el5_3.4.src.rpm
i386:
ghostscript-8.15.2-9.4.el5_3.4.i386.rpm
ghostscript-debuginfo-8.15.2-9.4.el5_3.4.i386.rpm
ghostscript-devel-8.15.2-9.4.el5_3.4.i386.rpm
ghostscript-gtk-8.15.2-9.4.el5_3.4.i386.rpm
ia64:
ghostscript-8.15.2-9.4.el5_3.4.ia64.rpm
ghostscript-debuginfo-8.15.2-9.4.el5_3.4.ia64.rpm
ghostscript-devel-8.15.2-9.4.el5_3.4.ia64.rpm
ghostscript-gtk-8.15.2-9.4.el5_3.4.ia64.rpm
ppc:
ghostscript-8.15.2-9.4.el5_3.4.ppc.rpm
ghostscript-8.15.2-9.4.el5_3.4.ppc64.rpm
ghostscript-debuginfo-8.15.2-9.4.el5_3.4.ppc.rpm
ghostscript-debuginfo-8.15.2-9.4.el5_3.4.ppc64.rpm
ghostscript-devel-8.15.2-9.4.el5_3.4.ppc.rpm
ghostscript-devel-8.15.2-9.4.el5_3.4.ppc64.rpm
ghostscript-gtk-8.15.2-9.4.el5_3.4.ppc.rpm
s390x:
ghostscript-8.15.2-9.4.el5_3.4.s390.rpm
ghostscript-8.15.2-9.4.el5_3.4.s390x.rpm
ghostscript-debuginfo-8.15.2-9.4.el5_3.4.s390.rpm
ghostscript-debuginfo-8.15.2-9.4.el5_3.4.s390x.rpm
ghostscript-devel-8.15.2-9.4.el5_3.4.s390.rpm
ghostscript-devel-8.15.2-9.4.el5_3.4.s390x.rpm
ghostscript-gtk-8.15.2-9.4.el5_3.4.s390x.rpm
x86_64:
ghostscript-8.15.2-9.4.el5_3.4.i386.rpm
ghostscript-8.15.2-9.4.el5_3.4.x86_64.rpm
ghostscript-debuginfo-8.15.2-9.4.el5_3.4.i386.rpm
ghostscript-debuginfo-8.15.2-9.4.el5_3.4.x86_64.rpm
ghostscript-devel-8.15.2-9.4.el5_3.4.i386.rpm
ghostscript-devel-8.15.2-9.4.el5_3.4.x86_64.rpm
ghostscript-gtk-8.15.2-9.4.el5_3.4.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package
7. References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0583
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0584
http://www.redhat.com/security/updates/classification/#moderate
8. Contact:
The Red Hat security contact is . More contact
details at https://www.redhat.com/security/team/contact/
Copyright 2009 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)
iD8DBQFJwm8EXlSAg2UNWIIRAjSaAKCb/pTzBf3CW4Z3ajz2GU8ZbzjAgwCgiWSN
kpZoxbKNVRKN5Pgw6l0Fc+s=
=RI13
-----END PGP SIGNATURE-----
"
RHSA-2009:0341-01 Moderate: curl security update
This entry was posted
on 3:55 AM
.
Archives
-
▼
2009
(488)
-
▼
March
(44)
- DSA 1760-1: New openswan packages fix denial of se...
- USN-750-1: OpenSSL vulnerability
- USN-748-1: OpenJDK vulnerabilities
- DSA 1756-1: New xulrunner packages fix multiple vu...
- RHSA-2009:0373-01 Moderate: systemtap security update
- RHSA-2009:0397-01 Critical: firefox security update
- RHSA-2009:0295-01 Moderate: net-snmp security update
- DSA 1755-1: New systemtap packages fix local privi...
- GLSA 200903-39 pam_krb5: Privilege escalation
- RHSA-2009:0394-01 Critical: java-1.5.0-sun securit...
- RHSA-2009:0376-01 Critical: acroread security update
- GLSA 200903-38 Squid: Multiple Denial of Service ...
- DSA 1753-1: End-of-life announcement for Iceweasel...
- GLSA 200903-35 Muttprint: Insecure temporary file...
- DSA 1747-1: New glib2.0 packages fix arbitrary cod...
- DSA 1750-1: New libpng packages fix several vulner...
- DSA 1748-1: New libsoup packages fix arbitrary cod...
- GLSA 200903-34 Amarok: User-assisted execution of...
- RHSA-2009:0345-01 Moderate: ghostscript security u...
- USN-742-1: JasPer vulnerabilities
- DSA 1749-1: New Linux 2.6.26 packages fix several ...
- RHSA-2009:0341-01 Moderate: curl security update
- GLSA 200903-32 phpMyAdmin: Multiple vulnerabilities
- DSA 1744-1: New weechat packages fix denial of ser...
- GLSA 200903-29 BlueZ: Arbitrary code execution
- RHSA-2009:0355-01 Moderate: evolution and evolutio...
- USN-737-1: libsoup vulnerability
- DSA 1743-1: New libtk-img packages fix arbitrary c...
- DSA 1740-1: New yaws packages fix denial of service
- DSA 1741-1: New psi packages fix denial of service
- DSA 1742-1: New libsnd packages fix arbitrary code...
- GLSA 200903-25 Courier Authentication Library: SQ...
- USN-731-1: Apache vulnerabilities
- GLSA 200903-26 TMSNC: Execution of arbitrary code
- DSA 1738-1: New curl packages fix arbitrary file a...
- DSA 1739-1: New mldonkey packages fix information ...
- RHSA-2009:0331-01 Important: kernel security and b...
- GLSA 200903-21 cURL: Arbitrary file access
- GLSA 200903-23 Adobe Flash Player: Multiple vulne...
- DSA 1735-1: New znc packages fix privilege escalation
- USN-732-1: dash vulnerability
- DSA 1737-1: New wesnoth packages fix several vulne...
- Media player targets embedded Linux devices
- TI die-shrinks OMAP3
-
▼
March
(44)