Mandriva Linux Security Advisory : ghostscript (MDVSA-2009:311)

Critical Nessus Plugin ID 42997

Synopsis

The remote Mandriva Linux host is missing one or more security updates.

Description

Multiple security vulnerabilities has been identified and fixed in ghostscript :

A buffer underflow in Ghostscript's CCITTFax decoding filter allows remote attackers to cause denial of service and possibly to execute arbitrary by using a crafted PDF file (CVE-2007-6725).

Buffer overflow in Ghostscript's BaseFont writer module allows remote attackers to cause a denial of service and possibly to execute arbitrary code via a crafted Postscript file (CVE-2008-6679).

Multiple interger overflows in Ghostsript's International Color Consortium Format Library (icclib) allows attackers to cause denial of service (heap-based buffer overflow and application crash) and possibly execute arbitrary code by using either a PostScript or PDF file with crafte embedded images (CVE-2009-0583, CVE-2009-0584).

Multiple interger overflows in Ghostsript's International Color Consortium Format Library (icclib) allows attackers to cause denial of service (heap-based buffer overflow and application crash) and possibly execute arbitrary code by using either a PostScript or PDF file with crafte embedded images. Note: this issue exists because of an incomplete fix for CVE-2009-0583 (CVE-2009-0792).

Heap-based overflow in Ghostscript's JBIG2 decoding library allows attackers to cause denial of service and possibly to execute arbitrary code by using a crafted PDF file (CVE-2009-0196).

Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation (CVE-2008-3520).

Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf (CVE-2008-3522).

Previousely the ghostscript packages were statically built against a bundled and private copy of the jasper library. This update makes ghostscript link against the shared system jasper library which makes it easier to address presumptive future security issues in the jasper library.

Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers

This update provides fixes for that vulnerabilities.

Solution

Update the affected packages.

Plugin Details

Severity: Critical

ID: 42997

File Name: mandriva_MDVSA-2009-311.nasl

Version: 1.18

Type: local

Published: 2009/12/04

Updated: 2019/08/02

Dependencies: 12634

Risk Information

Risk Factor: Critical

CVSS v2.0

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:ghostscript, p-cpe:/a:mandriva:linux:ghostscript-X, p-cpe:/a:mandriva:linux:ghostscript-common, p-cpe:/a:mandriva:linux:ghostscript-doc, p-cpe:/a:mandriva:linux:ghostscript-dvipdf, p-cpe:/a:mandriva:linux:ghostscript-module-X, p-cpe:/a:mandriva:linux:lib64gs8, p-cpe:/a:mandriva:linux:lib64gs8-devel, p-cpe:/a:mandriva:linux:lib64ijs1, p-cpe:/a:mandriva:linux:lib64ijs1-devel, p-cpe:/a:mandriva:linux:libgs8, p-cpe:/a:mandriva:linux:libgs8-devel, p-cpe:/a:mandriva:linux:libijs1, p-cpe:/a:mandriva:linux:libijs1-devel, cpe:/o:mandriva:linux:2008.0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2009/12/03

Reference Information

CVE: CVE-2007-6725, CVE-2008-3520, CVE-2008-3522, CVE-2008-6679, CVE-2009-0196, CVE-2009-0583, CVE-2009-0584, CVE-2009-0792

BID: 31470, 34184, 34337, 34340, 34445

MDVSA: 2009:311

CWE: 119, 189