USN-7103-1: Ghostscript vulnerabilities
It was discovered that Ghostscript incorrectly handled parsing certain PS files. An attacker could use this issue to cause Ghostscript to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2024-46951, CVE-2024-46953, CVE-2024-46955, CVE-2024-46956) It was discovered that Ghostscript incorrectly handled parsing certain PDF files. An attacker could use this issue to cause Ghostscript to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 24.10. (CVE-2024-46952) It was discovered that Ghostscript incorrectly handled parsing certain PS files. An attacker could use this issue to cause Ghostscript to crash, resulting in a denial of service, or possibly bypass file path validation. This issue only affected Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2024-46954)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7103-1?
The severity of USN-7103-1 is high due to potential denial of service and arbitrary code execution risks.
How do I fix USN-7103-1?
To fix USN-7103-1, you should upgrade to the latest patched version of Ghostscript or libgs based on your Ubuntu version.
What products are affected by USN-7103-1?
USN-7103-1 affects Ghostscript and libgs packages in various Ubuntu releases.
Can USN-7103-1 be exploited remotely?
Yes, attackers can potentially exploit USN-7103-1 remotely by sending crafted PS files to the affected system.
What are the potential impacts of USN-7103-1?
The potential impacts of USN-7103-1 include system crashes leading to denial of service and possible execution of arbitrary code.