Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2017.0355
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2017-0355)
Zusammenfassung:The remote host is missing an update for the 'ghostscript' package(s) announced via the MGASA-2017-0355 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'ghostscript' package(s) announced via the MGASA-2017-0355 advisory.

Vulnerability Insight:
The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS
9.21 allows remote attackers to cause a denial of service (heap-based
buffer over-read and application crash) or possibly have unspecified
other impact via a crafted document. (CVE-2017-9611)

The Ins_IP function in base/ttinterp.c in Artifex Ghostscript GhostXPS
9.21 allows remote attackers to cause a denial of service
(use-after-free and application crash) or possibly have unspecified
other impact via a crafted document. (CVE-2017-9612)

The Ins_MDRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS
9.21 allows remote attackers to cause a denial of service (heap-based
buffer over-read and application crash) or possibly have unspecified
other impact via a crafted document. (CVE-2017-9726)

The gx_ttfReader__Read function in base/gxttfb.c in Artifex Ghostscript
GhostXPS 9.21 allows remote attackers to cause a denial of service
(heap-based buffer over-read and application crash) or possibly have
unspecified other impact via a crafted document. (CVE-2017-9727)

The Ins_JMPR function in base/ttinterp.c in Artifex Ghostscript GhostXPS
9.21 allows remote attackers to cause a denial of service (heap-based
buffer over-read and application crash) or possibly have unspecified
other impact via a crafted document. (CVE-2017-9739)

The gs_alloc_ref_array function in psi/ialloc.c in Artifex Ghostscript
9.21 allows remote attackers to cause a denial of service (heap-based
buffer overflow and application crash) or possibly have unspecified
other impact via a crafted PostScript document. This is related to a
lack of an integer overflow check in base/gsalloc.c. (CVE-2017-9835)

psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the
scanner state structure, which allows remote attackers to cause a denial
of service (application crash) or possibly have unspecified other impact
via a crafted PostScript document, related to an out-of-bounds read in
the igc_reloc_struct_ptr function in psi/igc.c. (CVE-2017-11714)

Affected Software/OS:
'ghostscript' package(s) on Mageia 5, Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-11714
Debian Security Information: DSA-3986 (Google Search)
http://www.debian.org/security/2017/dsa-3986
https://security.gentoo.org/glsa/201811-12
http://www.securitytracker.com/id/1039233
Common Vulnerability Exposure (CVE) ID: CVE-2017-9611
BugTraq ID: 99975
http://www.securityfocus.com/bid/99975
Common Vulnerability Exposure (CVE) ID: CVE-2017-9612
BugTraq ID: 99979
http://www.securityfocus.com/bid/99979
Common Vulnerability Exposure (CVE) ID: CVE-2017-9726
BugTraq ID: 99992
http://www.securityfocus.com/bid/99992
Common Vulnerability Exposure (CVE) ID: CVE-2017-9727
BugTraq ID: 99999
http://www.securityfocus.com/bid/99999
Common Vulnerability Exposure (CVE) ID: CVE-2017-9739
BugTraq ID: 99987
http://www.securityfocus.com/bid/99987
Common Vulnerability Exposure (CVE) ID: CVE-2017-9835
BugTraq ID: 99991
http://www.securityfocus.com/bid/99991
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.