Format: 1.8 Date: Wed, 05 Jul 2023 12:56:27 -0400 Source: ghostscript Binary: ghostscript ghostscript-dbg ghostscript-x libgs-dev libgs9 Architecture: arm64 Version: 9.50~dfsg-5ubuntu4.8 Distribution: focal Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: ghostscript - interpreter for the PostScript language and for PDF ghostscript-dbg - interpreter for the PostScript language and for PDF - Debug symbo ghostscript-x - interpreter for the PostScript language and for PDF - X11 support libgs-dev - interpreter for the PostScript language and for PDF - Development libgs9 - interpreter for the PostScript language and for PDF - Library Changes: ghostscript (9.50~dfsg-5ubuntu4.8) focal-security; urgency=medium . * SECURITY UPDATE: incorrect permission validation for pipe devices - debian/patches/CVE-2023-36664-pre1.patch: improve handling of current directory permissions in base/gpmisc.c. - debian/patches/CVE-2023-36664-pre2.patch: fix gp_file allocations to use thread_safe_memory in base/gpmisc.c. - debian/patches/CVE-2023-36664-1.patch: don't reduce pipe file names for permission validation in base/gpmisc.c, base/gslibctx.c. - debian/patches/CVE-2023-36664-2.patch: fix logic and add extra test in base/gpmisc.c, base/gslibctx.c. - CVE-2023-36664 Checksums-Sha1: b51778c97a3f0debaac3bf0a6cb7e2a97478ea29 16750748 ghostscript-dbg_9.50~dfsg-5ubuntu4.8_arm64.deb 73ab3e607be91d928cc7298ef2e195456cb48283 42036 ghostscript-x_9.50~dfsg-5ubuntu4.8_arm64.deb 07b30cd7782072335150e1d9617a31700c32cc31 12844 ghostscript_9.50~dfsg-5ubuntu4.8_arm64.buildinfo db33425426c86e6c92806f4b422e37673c270331 51872 ghostscript_9.50~dfsg-5ubuntu4.8_arm64.deb 655c59cf9967dec289b020167ea410851fc93fd3 27372 libgs-dev_9.50~dfsg-5ubuntu4.8_arm64.deb 27f04ae3d870b41c5123fd2446e02ec7a1c6191d 2006696 libgs9_9.50~dfsg-5ubuntu4.8_arm64.deb Checksums-Sha256: 996a15ab25d2864fce3d6dfa1ac2763ee72a965de536c7781297e62b2c28b2a5 16750748 ghostscript-dbg_9.50~dfsg-5ubuntu4.8_arm64.deb 46f673f58d021654d2fbe0d5cdedd4aae29c6a3d99c5a88ad6ed8e95d9da052b 42036 ghostscript-x_9.50~dfsg-5ubuntu4.8_arm64.deb 80f7256274513abb1282c8ed36e1c733ea15c4d7aaf58f1b525859d54804a5ea 12844 ghostscript_9.50~dfsg-5ubuntu4.8_arm64.buildinfo 63e91a62b8f73c0c08424278baa8de7e45e2eb41f6dcc14073d9847426e6bdad 51872 ghostscript_9.50~dfsg-5ubuntu4.8_arm64.deb a2a03e985cc764f6347ee9bbfc1282012754566445201dd9f85b558daadbeec4 27372 libgs-dev_9.50~dfsg-5ubuntu4.8_arm64.deb 939a3abfca0ad5dfd2b7fbab5380a19a0c3ee0c872001d9dcdc35de706fcc5cd 2006696 libgs9_9.50~dfsg-5ubuntu4.8_arm64.deb Files: fe9e0eb14cfeb85f5d3eadc576c5a809 16750748 debug optional ghostscript-dbg_9.50~dfsg-5ubuntu4.8_arm64.deb b1b1b71f5ff3da6bcfc4a19747f8ecd0 42036 text optional ghostscript-x_9.50~dfsg-5ubuntu4.8_arm64.deb d37043c1862e388340513b9e4f8940be 12844 text optional ghostscript_9.50~dfsg-5ubuntu4.8_arm64.buildinfo 577183fa743b3fecd7ff41d108edbf13 51872 text optional ghostscript_9.50~dfsg-5ubuntu4.8_arm64.deb 214ce6cb5a5008ae2f7e46319f765373 27372 libdevel optional libgs-dev_9.50~dfsg-5ubuntu4.8_arm64.deb abff3d7b74b31fa8ee7a83afa0fc8784 2006696 libs optional libgs9_9.50~dfsg-5ubuntu4.8_arm64.deb Original-Maintainer: Debian Printing Team