Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.123998
Category:Oracle Linux Local Security Checks
Title:Oracle: Security Advisory (ELSA-2012-0095)
Summary:The remote host is missing an update for the 'ghostscript' package(s) announced via the ELSA-2012-0095 advisory.
Description:Summary:
The remote host is missing an update for the 'ghostscript' package(s) announced via the ELSA-2012-0095 advisory.

Vulnerability Insight:
[8.70-11:.6]
- Applied upstream fix to last patch (CVE-2010-4054, bug #646086).

[8.70-11:.5]
- Applied patch to prevent null pointer dereference (CVE-2010-4054,
bug #646086).

[8.70-11:.4]
- Don't ship patch backup files for CVE-2010-2055.

[8.70-11:.3]
- Applied patch to prevent integer underflow in TrueType bytecode
interpreter (CVE-2009-3743, bug #627902).
- Applied patch to avoid reading initialization files from CWD
(CVE-2010-2055, bug #599564).

Affected Software/OS:
'ghostscript' package(s) on Oracle Linux 5, Oracle Linux 6.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-3743
Bugtraq: 20101125 TSSA-2010-01 Ghostscript library Ins_MINDEX() integer overflow and heap corruption (Google Search)
http://www.securityfocus.com/archive/1/514892/100/0/threaded
CERT/CC vulnerability note: VU#644319
http://www.kb.cert.org/vuls/id/644319
http://security.gentoo.org/glsa/glsa-201412-17.xml
http://www.kb.cert.org/vuls/id/JALR-87YGN8
RedHat Security Advisories: RHSA-2012:0095
https://rhn.redhat.com/errata/RHSA-2012-0095.html
http://www.securitytracker.com/id?1024785
Common Vulnerability Exposure (CVE) ID: CVE-2010-2055
20100522 Ghostscript 8.64 executes random code at startup
http://www.securityfocus.com/archive/1/511433
20100526 Re: Ghostscript 8.64 executes random code at startup
http://www.securityfocus.com/archive/1/511472
http://www.securityfocus.com/archive/1/511474
http://www.securityfocus.com/archive/1/511476
40452
http://secunia.com/advisories/40452
40475
http://secunia.com/advisories/40475
40532
http://secunia.com/advisories/40532
66247
http://www.osvdb.org/66247
ADV-2010-1757
http://www.vupen.com/english/advisories/2010/1757
FEDORA-2010-10642
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043948.html
FEDORA-2010-10660
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043913.html
GLSA-201412-17
RHSA-2012:0095
SUSE-SR:2010:014
http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583183
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583316
http://bugs.ghostscript.com/show_bug.cgi?id=691339
http://bugs.ghostscript.com/show_bug.cgi?id=691350
http://savannah.gnu.org/forum/forum.php?forum_id=6368
https://bugzilla.novell.com/show_bug.cgi?id=608071
https://bugzilla.redhat.com/show_bug.cgi?id=599564
Common Vulnerability Exposure (CVE) ID: CVE-2010-4054
CERT/CC vulnerability note: VU#538191
http://www.kb.cert.org/vuls/id/538191
http://ghostscript.com/pipermail/gs-cvs/2010-January/010333.html
RedHat Security Advisories: RHSA-2012:0096
http://rhn.redhat.com/errata/RHSA-2012-0096.html
Common Vulnerability Exposure (CVE) ID: CVE-2010-4820
51847
http://www.securityfocus.com/bid/51847
http://rhn.redhat.com/errata/RHSA-2012-0095.html
RHSA-2012:0096
[oss-security] 20120104 Re: CVE request: ghostscript: system initialization file uncontrolled search path element
http://www.openwall.com/lists/oss-security/2012/01/04/7
https://bugzilla.redhat.com/show_bug.cgi?id=771853
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.