FlawAtlas
Search the atlas
SUSE-SU-2017:1404-1 Not scored

Security update for ghostscript

This update for ghostscript fixes the following security vulnerabilities: - CVE-2017-8291: A remote command execution and a -dSAFER bypass via a crafted .eps document were exploited in the wild. (bsc#1036453) - CVE-2016-9601: An integer overflow in the bundled jbig2dec library could have been misused to cause a Denial-of-Service. (bsc#1018128) - CVE-2016-10220: A NULL pointer dereference in the PDF Transparency module allowed remote attackers to cause a Denial-of-Service. (bsc#1032120) - CVE-2017-5951: A NULL pointer dereference allowed remote attackers to cause a denial of service via a crafted PostScript document. (bsc#1032114) - CVE-2017-7207: A NULL pointer dereference allowed remote attackers to cause a denial of service via a crafted PostScript document. (bsc#1030263) This is a reissue of the previous update to also include SUSE Linux Enterprise 12 GA LTSS packages.

Exploit probability Not scored
Published May 24, 2017
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Desktop 12 SP1 ghostscript
SUSE:Linux Enterprise Desktop 12 SP2 ghostscript
SUSE:Linux Enterprise Server 12 SP1 ghostscript
SUSE:Linux Enterprise Server 12 SP2 ghostscript
SUSE:Linux Enterprise Server 12-LTSS ghostscript
SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2 ghostscript
SUSE:Linux Enterprise Server for SAP Applications 12 ghostscript
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 ghostscript
SUSE:Linux Enterprise Server for SAP Applications 12 SP2 ghostscript
SUSE:Linux Enterprise Software Development Kit 12 SP1 ghostscript
SUSE:Linux Enterprise Software Development Kit 12 SP2 ghostscript

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2017:1404-1

This update for ghostscript fixes the following security vulnerabilities: - CVE-2017-8291: A remote command execution and a -dSAFER bypass via a crafted .eps document were exploited in the wild. (bsc#1036453) - CVE-2016-9601: An integer overflow in the bundled jbig2dec library could have been misused to cause a Denial-of-Service. (bsc#1018128) - CVE-2016-10220: A NULL pointer dereference in the PDF Transparency module allowed remote attackers to cause a Denial-of-Service. (bsc#1032120) - CVE-2017-5951: A NULL pointer dereference allowed remote attackers to cause a denial of service via a crafted PostScript document. (bsc#1032114) - CVE-2017-7207: A NULL pointer dereference allowed remote attackers to cause a denial of service via a crafted PostScript document. (bsc#1030263) This is a reissue of the previous update to also include SUSE Linux Enterprise 12 GA LTSS packages.

View original source

05 / REFERENCES

Further evidence