Summary: | <app-text/ghostscript-gpl-9.26: improperly implemented security check in zsetdevice function in psi/zdevice.c (CVE-2018-19409) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | GLSAMaker/CVETool Bot <glsamaker> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | printing |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B1 [glsa+ glsa+ blocked cve] | ||
Package list: |
app-text/ghostscript-gpl-9.26
|
Runtime testing required: | --- |
Bug Depends on: | 668846 | ||
Bug Blocks: |
Description
GLSAMaker/CVETool Bot
2018-11-23 01:42:28 UTC
Raising severity, can be used in a combined attack involving less to get root. This issue was resolved and addressed in GLSA 201811-12 at https://security.gentoo.org/glsa/201811-12 by GLSA coordinator Aaron Bauman (b-man). |