Summary: | <app-text/ghostscript-gpl-9.25: Out of bounds read in igc_reloc_struct_ptr() (CVE-2017-11714) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Aleksandr Wagner (Kivak) <alwag> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | printing |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1476192 | ||
Whiteboard: | B3 [glsa+ cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 635426 | ||
Bug Blocks: |
Description
Aleksandr Wagner (Kivak)
2017-07-28 09:37:01 UTC
See also [1]. This is included in [2] which also fixes several other ghostscript CVEs, none of which seem to exist as bugs in gentoo. [1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=869977 [2] https://www.debian.org/security/2017/dsa-3986 This bug should depend on bug 634616, a bump request to ghostscript 9.22. Maintainers, the fix is in the 9.22. Please bump. Michael Boyle Gentoo Security Padawan This issue was resolved and addressed in GLSA 201811-12 at https://security.gentoo.org/glsa/201811-12 by GLSA coordinator Aaron Bauman (b-man). |