USN-1581-1: Ghostscript vulnerability
Ubuntu Security Notice USN-1581-1
24th September, 2012
ghostscript vulnerability
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS
Summary
Ghostscript could be made to crash or run programs as your login if it opened a specially crafted file.
Software description
- ghostscript - The GPL Ghostscript PostScript/PDF interpreter
Details
Marc Schönefeld discovered that Ghostscript did not correctly handle
certain image files. If a user or automated system were tricked into
opening a specially crafted file, an attacker could cause a denial of
service and possibly execute arbitrary code with user privileges.
Update instructions
The problem can be corrected by updating your system to the following package version:
- Ubuntu 10.04 LTS:
- libgs8 8.71.dfsg.1-0ubuntu5.5
- Ubuntu 8.04 LTS:
- libgs8 8.61.dfsg.1-1ubuntu3.5
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
In general, a standard system update will make all the necessary changes.