Debian Package Tracker
Register | Log in
Subscribe

ghostscript

interpreter for the PostScript language and for PDF

Choose email to subscribe with

general
  • source: ghostscript (main)
  • version: 10.08.0~dfsg-2
  • maintainer: Debian Printing Team (archive) (DMD) (LowNMU)
  • uploaders: Steve M. Robbins [DMD]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 9.53.3~dfsg-7+deb11u7
  • o-o-sec: 9.53.3~dfsg-7+deb11u11
  • oldstable: 10.0.0~dfsg-11+deb12u8
  • old-sec: 10.0.0~dfsg-11+deb12u8
  • stable: 10.05.1~dfsg-1+deb13u1
  • stable-sec: 10.05.1~dfsg-1+deb13u2
  • testing: 10.08.0~dfsg-2
  • unstable: 10.08.0~dfsg-2
versioned links
  • 9.53.3~dfsg-7+deb11u7: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 9.53.3~dfsg-7+deb11u11: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 10.0.0~dfsg-11+deb12u8: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 10.05.1~dfsg-1+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 10.05.1~dfsg-1+deb13u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 10.08.0~dfsg-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ghostscript (10 bugs: 0, 3, 7, 0)
  • ghostscript-doc
  • libgs-common
  • libgs-dev
  • libgs10
  • libgs10-common
action needed
3 security issues in bookworm high

There are 3 open security issues in bookworm.

3 important issues:
  • CVE-2026-39919: Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates a row buffer sized for packed output but writes a full byte per output column regardless of bit depth, overflowing the allocation and corrupting internal chunk-allocator metadata to achieve code execution.
  • CVE-2026-103226:
  • TEMP-0000000-E17884:
Created: 2026-09-22 Last update: 2026-09-30 21:31
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-103226:
Created: 2026-09-30 Last update: 2026-09-30 21:31
Depends on packages which need a new maintainer normal
The packages that ghostscript depends on which need a new maintainer are:
  • dh-linktree (#980413)
    • Build-Depends: dh-linktree
Created: 2021-01-18 Last update: 2026-10-01 06:31
1 open merge request in Salsa normal
There is 1 open merge request for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2026-09-30 Last update: 2026-09-30 21:31
lintian reports 449 warnings normal
Lintian reports 449 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-09-12 Last update: 2026-09-12 22:30
debian/patches: 3 patches to forward upstream low

Among the 13 debian patches available in version 10.08.0~dfsg-2 of the package, we noticed the following issues:

  • 3 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-09-23 13:30
news
[rss feed]
  • [2026-09-28] ghostscript 10.08.0~dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2026-09-25] Accepted ghostscript 10.05.1~dfsg-1+deb13u2 (source) into stable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-09-23] Accepted ghostscript 10.08.0~dfsg-2 (source) into unstable (Steve M. Robbins)
  • [2026-09-12] Accepted ghostscript 10.08.0~dfsg-1 (source amd64 all) into unstable (Steve M. Robbins)
  • [2026-05-30] ghostscript 10.07.1~dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-24] Accepted ghostscript 10.07.1~dfsg-1 (source) into unstable (Steve M. Robbins)
  • [2026-03-26] ghostscript 10.07.0~dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2026-03-23] Accepted ghostscript 10.07.0~dfsg-2 (source) into unstable (Steve M. Robbins)
  • [2026-03-23] Accepted ghostscript 10.07.0~dfsg-1 (source) into unstable (Steve M. Robbins)
  • [2025-11-15] ghostscript 10.06.0~dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2025-10-19] Accepted ghostscript 10.0.0~dfsg-11+deb12u8 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2025-10-14] Accepted ghostscript 9.53.3~dfsg-7+deb11u11 (source) into oldoldstable-security (Abhijith PA)
  • [2025-10-13] Accepted ghostscript 10.05.1~dfsg-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2025-10-11] Accepted ghostscript 10.0.0~dfsg-11+deb12u8 (source) into oldstable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2025-10-11] Accepted ghostscript 10.05.1~dfsg-1+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2025-10-01] Accepted ghostscript 10.06.0~dfsg-3 (source) into unstable (Steve M. Robbins)
  • [2025-09-30] Accepted ghostscript 10.06.0~dfsg-2 (source) into unstable (Steve M. Robbins)
  • [2025-09-29] Accepted ghostscript 10.06.0~dfsg-1 (source amd64 all) into unstable (Steve M. Robbins)
  • [2025-09-11] ghostscript 10.05.1~dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2025-09-07] Accepted ghostscript 10.05.1~dfsg-3 (source) into unstable (Steve M. Robbins)
  • [2025-08-31] ghostscript 10.05.1~dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2025-08-24] Accepted ghostscript 10.05.1~dfsg-2 (source) into unstable (Steve M. Robbins)
  • [2025-05-15] ghostscript 10.05.1~dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-05-05] Accepted ghostscript 10.05.1~dfsg-1 (source) into unstable (Steve M. Robbins)
  • [2025-04-07] Accepted ghostscript 9.53.3~dfsg-7+deb11u10 (source) into oldstable-security (Adrian Bunk)
  • [2025-03-27] Accepted ghostscript 10.0.0~dfsg-11+deb12u7 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2025-03-26] Accepted ghostscript 10.0.0~dfsg-11+deb12u7 (source) into stable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2025-03-19] ghostscript 10.05.0~dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-16] Accepted ghostscript 10.05.0~dfsg-1 (source) into unstable (Steve M. Robbins)
  • [2024-12-07] ghostscript 10.04.0~dfsg-2 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 9 10
  • RC: 0
  • I&N: 3
  • M&W: 6 7
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 449)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 10.07.1~dfsg-1ubuntu2
  • 42 bugs
  • patches for 10.07.1~dfsg-1ubuntu2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing