Format: 1.8 Date: Tue, 29 Nov 2016 15:48:57 -0600 Source: ghostscript Binary: ghostscript ghostscript-x ghostscript-doc libgs9 libgs9-common libgs-dev ghostscript-dbg Architecture: powerpc Version: 9.18~dfsg~0-0ubuntu2.2 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Emily Ratliff Description: ghostscript - interpreter for the PostScript language and for PDF ghostscript-dbg - interpreter for the PostScript language and for PDF - Debug symbo ghostscript-doc - interpreter for the PostScript language and for PDF - Documentati ghostscript-x - interpreter for the PostScript language and for PDF - X11 support libgs-dev - interpreter for the PostScript language and for PDF - Development libgs9 - interpreter for the PostScript language and for PDF - Library libgs9-common - interpreter for the PostScript language and for PDF - common file Changes: ghostscript (9.18~dfsg~0-0ubuntu2.2) xenial-security; urgency=medium . * SECURITY UPDATE: Information disclosure through getenv, filenameforall - debian/patches/CVE-2013-5653.patch: Have filenameforall and getenv honor SAFER - CVE-2013-5653 * SECURITY UPDATE: userparams with %pipe% in paths allow remote shell exec - debian/patches/CVE-2016-7976.patch: Add a file permissions callback - CVE-2016-7976 * SECURITY UPDATE: Improve SAFER permission handling - debian/patches/safer.patch: Be rigorous with SAFER permissions * SECURITY UPDATE: use-after-free and remote code execution - debian/patches/CVE-2016-7978.patch: Reference count device icc profile - CVE-2016-7978 * SECURITY UPDATE: type confusion allows remote code execution - debian/patches/CVE-2016-7979.patch: DSC parser - validate parameters - CVE-2016-7979 * SECURITY UPDATE: NULL dereference - debian/patches/CVE-2016-8602.patch: check for sufficient params - CVE-2016-8602 Checksums-Sha1: 49a0718d368e937324b18bff878203c9dfbb7fe1 5403894 ghostscript-dbg_9.18~dfsg~0-0ubuntu2.2_powerpc.deb 94331f511233a20f6c520faa888a0140ab748574 1004 ghostscript-dbgsym_9.18~dfsg~0-0ubuntu2.2_powerpc.ddeb 08bfe9ee2688d4517f3b0650a1034f4a69b94079 942 ghostscript-x-dbgsym_9.18~dfsg~0-0ubuntu2.2_powerpc.ddeb e4249c58e660f95ad880f12c6cbbd65e11c52aaa 32958 ghostscript-x_9.18~dfsg~0-0ubuntu2.2_powerpc.deb 32933cf9e28321dc3ad565f0389dfc76db244c76 40906 ghostscript_9.18~dfsg~0-0ubuntu2.2_powerpc.deb 1a65ce1100ccdcfbe2ea9953087919ebcae0b67f 998 libgs-dev-dbgsym_9.18~dfsg~0-0ubuntu2.2_powerpc.ddeb f05cc196001389350676219b733ae42acc00ca45 2062576 libgs-dev_9.18~dfsg~0-0ubuntu2.2_powerpc.deb 2bf845e8a8e7cd448ad5b36f1e5fe67dbdf24cec 984 libgs9-dbgsym_9.18~dfsg~0-0ubuntu2.2_powerpc.ddeb b1e84376b61ea03191c149d5daef4293d387c7bd 1792250 libgs9_9.18~dfsg~0-0ubuntu2.2_powerpc.deb Checksums-Sha256: 33ad29a67e1d152166535d7928cd17a7c041c7772719cbe0cd704538530b24c8 5403894 ghostscript-dbg_9.18~dfsg~0-0ubuntu2.2_powerpc.deb 47bab345aab4b513d2788b95517fa6b21d19b778819fd6a5825029e1aabba686 1004 ghostscript-dbgsym_9.18~dfsg~0-0ubuntu2.2_powerpc.ddeb 07fd7594d596399e0991120be6e31ee8d249720eb1ec236d765daac4fe9ca437 942 ghostscript-x-dbgsym_9.18~dfsg~0-0ubuntu2.2_powerpc.ddeb 90271724594d64d027b368d7856959566b2faf97f1582584936e90c913365f90 32958 ghostscript-x_9.18~dfsg~0-0ubuntu2.2_powerpc.deb 7a6e0c462531db82f19bef05941c9cc1338bfa23fc2929311aa46316f7251e01 40906 ghostscript_9.18~dfsg~0-0ubuntu2.2_powerpc.deb 0538631060ba5fced36c6a97589140fba7e8b9b211203476a9f3c63f25cfa35b 998 libgs-dev-dbgsym_9.18~dfsg~0-0ubuntu2.2_powerpc.ddeb 38f17101a33864920c254ae8761bb990999ae514e5d1e4612348e593926f5ded 2062576 libgs-dev_9.18~dfsg~0-0ubuntu2.2_powerpc.deb 5200123a5ec4c8b0b00317096ca9ca55421f5ab839f5aa1be789a4b36b68cde5 984 libgs9-dbgsym_9.18~dfsg~0-0ubuntu2.2_powerpc.ddeb b37ab8aec49a226dce42b15bef08409d0e0f789682b4ac5f4fdabb5a914dd9ce 1792250 libgs9_9.18~dfsg~0-0ubuntu2.2_powerpc.deb Files: eb72a8203d7e55d1ddfbeb22b94a56bc 5403894 debug extra ghostscript-dbg_9.18~dfsg~0-0ubuntu2.2_powerpc.deb 3939193a759d4918bdbf63f1d5edff90 1004 text extra ghostscript-dbgsym_9.18~dfsg~0-0ubuntu2.2_powerpc.ddeb 1d075d6d27dba56d3e9dc3d9994c353a 942 text extra ghostscript-x-dbgsym_9.18~dfsg~0-0ubuntu2.2_powerpc.ddeb 7c00583289717369e0b3b61127ac40fc 32958 text optional ghostscript-x_9.18~dfsg~0-0ubuntu2.2_powerpc.deb 22e3018cd054d5cf6f88c6baf69f525f 40906 text optional ghostscript_9.18~dfsg~0-0ubuntu2.2_powerpc.deb f44cbe984ef2a0d2bd93855129168190 998 libdevel extra libgs-dev-dbgsym_9.18~dfsg~0-0ubuntu2.2_powerpc.ddeb aff4e14c7133d4869f86424561f2d676 2062576 libdevel optional libgs-dev_9.18~dfsg~0-0ubuntu2.2_powerpc.deb bdb714ad43f92a0694115c63fc6d1a1d 984 libs extra libgs9-dbgsym_9.18~dfsg~0-0ubuntu2.2_powerpc.ddeb c9546e7d690e8480953780c12723eca0 1792250 libs optional libgs9_9.18~dfsg~0-0ubuntu2.2_powerpc.deb Original-Maintainer: Debian Printing Team