-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 22 Oct 2018 12:50:48 +0200 Source: ghostscript Binary: ghostscript ghostscript-x ghostscript-doc libgs9 libgs9-common libgs-dev ghostscript-dbg Architecture: source all amd64 Version: 9.06~dfsg-2+deb8u11 Distribution: jessie-security Urgency: high Maintainer: Debian Printing Team <debian-printing@lists.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: ghostscript - interpreter for the PostScript language and for PDF ghostscript-dbg - interpreter for the PostScript language and for PDF - Debug symbo ghostscript-doc - interpreter for the PostScript language and for PDF - Documentati ghostscript-x - interpreter for the PostScript language and for PDF - X11 support libgs-dev - interpreter for the PostScript language and for PDF - Development libgs9 - interpreter for the PostScript language and for PDF - Library libgs9-common - interpreter for the PostScript language and for PDF - common file Changes: ghostscript (9.06~dfsg-2+deb8u11) jessie-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2018-17961, CVE-2018-18073 and CVE-2018-18284: This is a follow-up update for the recently discovered -dSAFER issues reported by Tavis Ormandy. Tavis Ormandy discovered multiple vulnerabilites in Ghostscript, an interpreter for the PostScript language, which could result in denial of service, the creation of files or the execution of arbitrary code if a malformed Postscript file is processed (despite the dSAFER sandbox being enabled). Checksums-Sha1: eb7ceab92aa459e2a31e6a2063a7ce021891a6a3 3047 ghostscript_9.06~dfsg-2+deb8u11.dsc 5c2abc0159af39446c79a0581dd95e2474bba977 148852 ghostscript_9.06~dfsg-2+deb8u11.debian.tar.xz 84e0f9e46270581fdfee35dd2568062a82881731 5160490 ghostscript-doc_9.06~dfsg-2+deb8u11_all.deb af2d85f95f65fe6583c80930f91f5b9a482d38ca 1972742 libgs9-common_9.06~dfsg-2+deb8u11_all.deb ad2e5978c18fca2fcf4efe2eea00eeef67a62b0c 85642 ghostscript_9.06~dfsg-2+deb8u11_amd64.deb 31ea314a53d3b9927a5a80632019422246f573ff 76718 ghostscript-x_9.06~dfsg-2+deb8u11_amd64.deb 5f0497a0ad482455010c158c96ba9812d9ef5642 1917418 libgs9_9.06~dfsg-2+deb8u11_amd64.deb 21b322848db6f2ad45cf891815f94486eadfa5e6 2122660 libgs-dev_9.06~dfsg-2+deb8u11_amd64.deb 0922c3e49215b97a6d78ee6aa059a91b3c8c71e6 4879750 ghostscript-dbg_9.06~dfsg-2+deb8u11_amd64.deb Checksums-Sha256: 1b0b489edc2efd46ac8ae29a1db931ce8a9f54c2eda7b63460a1862a9d8f27eb 3047 ghostscript_9.06~dfsg-2+deb8u11.dsc e65e5c0cc016eefc17b0d472b6e5e24bd96cbc9b722fde949366fb991c13fe6b 148852 ghostscript_9.06~dfsg-2+deb8u11.debian.tar.xz 7295bbd796f644de8f50f68cd4734b1273ed5bf00efed4fa5f496fb35fb26b74 5160490 ghostscript-doc_9.06~dfsg-2+deb8u11_all.deb 8fc81ec479dd1b417e54184c5a0349a9c18f36e87f4a57ec682befcc14c50289 1972742 libgs9-common_9.06~dfsg-2+deb8u11_all.deb 5d0a80034b57789861415840f29c3bcd1301575ebff2eb7a831c5fa795dd55da 85642 ghostscript_9.06~dfsg-2+deb8u11_amd64.deb becb8d444aa9c8852383df2c39b8bba9b5e23f5a93d1f45b6a84355c7ddc1863 76718 ghostscript-x_9.06~dfsg-2+deb8u11_amd64.deb 6dc6733b61734610783283341b4977c330a77f1021267686a0394eb2cecd1b69 1917418 libgs9_9.06~dfsg-2+deb8u11_amd64.deb 6fc161d72b8090462b5ef10fca525c8ed61c80d043061e09102b249923210c65 2122660 libgs-dev_9.06~dfsg-2+deb8u11_amd64.deb e8d9930465b65f253c16c3cb09b22f61ff0dc914a62c133e6facd63b70d101f4 4879750 ghostscript-dbg_9.06~dfsg-2+deb8u11_amd64.deb Files: b8b5c2ecdc68b07142c1e71353c72c26 3047 text optional ghostscript_9.06~dfsg-2+deb8u11.dsc 5f9bed931882691647ab4e724fb07f87 148852 text optional ghostscript_9.06~dfsg-2+deb8u11.debian.tar.xz cb942e3d3d6a356f535ee0a2ee2edf81 5160490 doc optional ghostscript-doc_9.06~dfsg-2+deb8u11_all.deb d2f33960f8f4568df892e2e3224850f2 1972742 libs optional libgs9-common_9.06~dfsg-2+deb8u11_all.deb 373d1df3630a57a54515080d021859e4 85642 text optional ghostscript_9.06~dfsg-2+deb8u11_amd64.deb 8bd0ae2e257f9d4d2d3c15ff2a856a75 76718 text optional ghostscript-x_9.06~dfsg-2+deb8u11_amd64.deb b14c8362ef4e019503a1311cbfca1bef 1917418 libs optional libgs9_9.06~dfsg-2+deb8u11_amd64.deb 99ff58e14065f8c553d1ad0f046f450f 2122660 libdevel optional libgs-dev_9.06~dfsg-2+deb8u11_amd64.deb c8b9c8e81d0ccdae3e299f973e3add2f 4879750 debug extra ghostscript-dbg_9.06~dfsg-2+deb8u11_amd64.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlvNrkNfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HksewP/03z3BzEuCb3DgsqF/n3dC0QhWcAfA3PoqG1 taBazwbpk17ZnoY47RS5F+5h+uPCCq/o+a6VLl62PkLdv8ThbkMLR+56gsCsjQ3v OwGPPt8qp8JZZRTvqpS24dYCmuxoKZ1hz4PIsUpQ+mzOxfn7jALwqH1v9CDzAzde tVCfXff9jws6G9e7rbaRQFu9pRrJjsCxtWHX5qaTboMrlvgyfl0fTgKIxK1XwlvG 1i2pWO06R78vDJziWMOV7oFqXCbsRzQAGDS4jWzuSMzkjkE0gg8KfPFSGSjzZYoy ilFkBr3hJWqBmOGjg9PMoHxoYoCxgbKxMX4yH40DBjPkBIqYahnKEkvuExJ2lVYU N7u2Eun/hKt+dKe5nJqL93MDL7ZaRJUM9XPcwLQja+LxTe2/BJ/pw4jAf4uEjzHH k9zpInxOBTMANvq1Oa0hOsZXBHnGMevdPIkehKeYc63S1Mi+4htQCni1n1DWMsdg ze98C1I3tkEuGJmBdYtPKAM/o6CM61GJA2zUNE6orzeMHgLhbG3et5uy80VcPKE7 aAGeOaqFwKab2a/jQFWWRzXPPiBtN8RYpJX8Xtw/s3zaGvFeegb+Olwt+TOQ8yii bTVSefkjfQCw823i1Wu/eZEa7GiZJkDpcJAMeWMt8zTkHsyydvLvKQTYSI+xXPZc 41k6cKtL =q6dX -----END PGP SIGNATURE-----