Ghostscript is an interpreter for PostScript™ and Portable Document Format (PDF) files. Ghostscript consists of a PostScript interpreter layer, and a graphics library.
Security Fix(es):
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.(CVE-2024-29507)
An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.(CVE-2024-33871)
{
"severity": "High"
}{
"noarch": [
"ghostscript-help-9.55.0-17.oe2203sp4.noarch.rpm"
],
"aarch64": [
"ghostscript-9.55.0-17.oe2203sp4.aarch64.rpm",
"ghostscript-debuginfo-9.55.0-17.oe2203sp4.aarch64.rpm",
"ghostscript-debugsource-9.55.0-17.oe2203sp4.aarch64.rpm",
"ghostscript-devel-9.55.0-17.oe2203sp4.aarch64.rpm",
"ghostscript-tools-dvipdf-9.55.0-17.oe2203sp4.aarch64.rpm"
],
"x86_64": [
"ghostscript-9.55.0-17.oe2203sp4.x86_64.rpm",
"ghostscript-debuginfo-9.55.0-17.oe2203sp4.x86_64.rpm",
"ghostscript-debugsource-9.55.0-17.oe2203sp4.x86_64.rpm",
"ghostscript-devel-9.55.0-17.oe2203sp4.x86_64.rpm",
"ghostscript-tools-dvipdf-9.55.0-17.oe2203sp4.x86_64.rpm"
],
"src": [
"ghostscript-9.55.0-17.oe2203sp4.src.rpm"
]
}