Ghostscript is an interpreter for PostScript™ and Portable Document Format (PDF) files. Ghostscript consists of a PostScript interpreter layer, and a graphics library.
Security Fix(es):
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdfbasefont_alloc.(CVE-2024-29508)
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.(CVE-2024-29510)
{
"severity": "Medium"
}{
"x86_64": [
"ghostscript-9.55.0-10.oe2203sp1.x86_64.rpm",
"ghostscript-debuginfo-9.55.0-10.oe2203sp1.x86_64.rpm",
"ghostscript-debugsource-9.55.0-10.oe2203sp1.x86_64.rpm",
"ghostscript-devel-9.55.0-10.oe2203sp1.x86_64.rpm",
"ghostscript-tools-dvipdf-9.55.0-10.oe2203sp1.x86_64.rpm"
],
"src": [
"ghostscript-9.55.0-10.oe2203sp1.src.rpm"
],
"aarch64": [
"ghostscript-9.55.0-10.oe2203sp1.aarch64.rpm",
"ghostscript-debuginfo-9.55.0-10.oe2203sp1.aarch64.rpm",
"ghostscript-debugsource-9.55.0-10.oe2203sp1.aarch64.rpm",
"ghostscript-devel-9.55.0-10.oe2203sp1.aarch64.rpm",
"ghostscript-tools-dvipdf-9.55.0-10.oe2203sp1.aarch64.rpm"
],
"noarch": [
"ghostscript-help-9.55.0-10.oe2203sp1.noarch.rpm"
]
}