First published: Wed May 08 2019(Updated: )
It was discovered that Ghostscript incorrectly handled certain PostScript files. If a user or automated system were tricked into processing a specially crafted file, a remote attacker could possibly use this issue to access arbitrary files, execute arbitrary code, or cause a denial of service.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/ghostscript | <9.26~dfsg+0-0ubuntu7.1 | 9.26~dfsg+0-0ubuntu7.1 |
Ubuntu | =19.04 | |
All of | ||
ubuntu/libgs9 | <9.26~dfsg+0-0ubuntu7.1 | 9.26~dfsg+0-0ubuntu7.1 |
Ubuntu | =19.04 | |
All of | ||
ubuntu/ghostscript | <9.26~dfsg+0-0ubuntu0.18.10.9 | 9.26~dfsg+0-0ubuntu0.18.10.9 |
Ubuntu | =18.10 | |
All of | ||
ubuntu/libgs9 | <9.26~dfsg+0-0ubuntu0.18.10.9 | 9.26~dfsg+0-0ubuntu0.18.10.9 |
Ubuntu | =18.10 | |
All of | ||
ubuntu/ghostscript | <9.26~dfsg+0-0ubuntu0.18.04.9 | 9.26~dfsg+0-0ubuntu0.18.04.9 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/libgs9 | <9.26~dfsg+0-0ubuntu0.18.04.9 | 9.26~dfsg+0-0ubuntu0.18.04.9 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/ghostscript | <9.26~dfsg+0-0ubuntu0.16.04.9 | 9.26~dfsg+0-0ubuntu0.16.04.9 |
Ubuntu | =16.04 | |
All of | ||
ubuntu/libgs9 | <9.26~dfsg+0-0ubuntu0.16.04.9 | 9.26~dfsg+0-0ubuntu0.16.04.9 |
Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-3970-1 is considered high due to the potential for remote code execution and access to arbitrary files.
To fix USN-3970-1, update Ghostscript and libgs9 to the recommended versions for your Ubuntu distribution.
USN-3970-1 affects Ubuntu versions 16.04, 18.04, 18.10, and 19.04 with specific Ghostscript and libgs9 package versions.
The risks associated with USN-3970-1 include the potential for attackers to execute arbitrary code or cause a denial of service.
Yes, USN-3970-1 is classified as a critical vulnerability due to its implications for security and system integrity.