Format: 1.8 Date: Wed, 05 Jul 2023 12:56:27 -0400 Source: ghostscript Binary: ghostscript ghostscript-dbg ghostscript-x libgs-dev libgs9 Architecture: i386 Version: 9.50~dfsg-5ubuntu4.8 Distribution: focal Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: ghostscript - interpreter for the PostScript language and for PDF ghostscript-dbg - interpreter for the PostScript language and for PDF - Debug symbo ghostscript-x - interpreter for the PostScript language and for PDF - X11 support libgs-dev - interpreter for the PostScript language and for PDF - Development libgs9 - interpreter for the PostScript language and for PDF - Library Changes: ghostscript (9.50~dfsg-5ubuntu4.8) focal-security; urgency=medium . * SECURITY UPDATE: incorrect permission validation for pipe devices - debian/patches/CVE-2023-36664-pre1.patch: improve handling of current directory permissions in base/gpmisc.c. - debian/patches/CVE-2023-36664-pre2.patch: fix gp_file allocations to use thread_safe_memory in base/gpmisc.c. - debian/patches/CVE-2023-36664-1.patch: don't reduce pipe file names for permission validation in base/gpmisc.c, base/gslibctx.c. - debian/patches/CVE-2023-36664-2.patch: fix logic and add extra test in base/gpmisc.c, base/gslibctx.c. - CVE-2023-36664 Checksums-Sha1: e0a7c23e1db1ec38cc260be0b98a8cb798948425 15965960 ghostscript-dbg_9.50~dfsg-5ubuntu4.8_i386.deb 2610268df17142bc9e6a609671c72f7a47cf4780 45788 ghostscript-x_9.50~dfsg-5ubuntu4.8_i386.deb b795b439eba4e51dca88056f2cd00bd2bde46b1d 12870 ghostscript_9.50~dfsg-5ubuntu4.8_i386.buildinfo 3c01f4947a925a550d8eac293eee15e525730679 52068 ghostscript_9.50~dfsg-5ubuntu4.8_i386.deb 1f80608ba1a6ea147006cf6b8a268e47381834a6 27372 libgs-dev_9.50~dfsg-5ubuntu4.8_i386.deb 8296e4c8cb1786f32e6a465215ed0e6e2f60c336 2279760 libgs9_9.50~dfsg-5ubuntu4.8_i386.deb Checksums-Sha256: 5b51f6f21b9540915a6936c86b73b70742744e32737f3ffd180a7c295925e183 15965960 ghostscript-dbg_9.50~dfsg-5ubuntu4.8_i386.deb 0debe9e4ef4a86130ce5f77eb5681ffa1b51dadd863cb7d46f969a10d7003df5 45788 ghostscript-x_9.50~dfsg-5ubuntu4.8_i386.deb 1460175c34a49fd2725a0fc53e1deb353720ba3a2bf5d2f68152538772af4be6 12870 ghostscript_9.50~dfsg-5ubuntu4.8_i386.buildinfo fa21616aed9a042a9b557b33c8e50e923b3c82181916d5de82922f4591a091d4 52068 ghostscript_9.50~dfsg-5ubuntu4.8_i386.deb ba7b03eacfa4f5372b422f193505f8a5b899288ffb6b78e76da1e40f9045dfd6 27372 libgs-dev_9.50~dfsg-5ubuntu4.8_i386.deb d306da30e9f46e0ab0748f8e4e08a14c027fbe4b704faa22c03e791aca46e8e3 2279760 libgs9_9.50~dfsg-5ubuntu4.8_i386.deb Files: 871a90f11cfa5773a26f59203e130049 15965960 debug optional ghostscript-dbg_9.50~dfsg-5ubuntu4.8_i386.deb 19311fce29852bff684fcd08e16f424d 45788 text optional ghostscript-x_9.50~dfsg-5ubuntu4.8_i386.deb d79d9d27ef18cbfb18c57719cf3e9465 12870 text optional ghostscript_9.50~dfsg-5ubuntu4.8_i386.buildinfo cf382fde4fec6e185a2370b72f5106bb 52068 text optional ghostscript_9.50~dfsg-5ubuntu4.8_i386.deb 1d16b15cdb2c6d9f9358c5b9ded347d3 27372 libdevel optional libgs-dev_9.50~dfsg-5ubuntu4.8_i386.deb c6eb7dd600e0272dd1551979c79a9bc3 2279760 libs optional libgs9_9.50~dfsg-5ubuntu4.8_i386.deb Original-Maintainer: Debian Printing Team