Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 910294 (CVE-2023-36664)

Summary: <app-text/ghostscript-gpl-10.01.2: Code execution vulnerability
Product: Gentoo Security Reporter: Hanno Böck <hanno>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: IN_PROGRESS ---    
Severity: critical CC: codec, printing
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://www.kroll.com/en/insights/publications/cyber/ghostscript-cve-2023-36664-remote-code-execution-vulnerability
Whiteboard: A2 [glsa+ stable]
Package list:
Runtime testing required: ---
Bug Depends on: 910308    
Bug Blocks:    

Description Hanno Böck gentoo-dev 2023-07-13 13:31:45 UTC
This sounds bad:
https://www.kroll.com/en/insights/publications/cyber/ghostscript-cve-2023-36664-remote-code-execution-vulnerability

10.01.2, which contains the fix, is already in the tree, but not yet stabilized.
Comment 1 Maxxim 2023-07-13 16:28:22 UTC
Version 10.01.2 should be stabilized asap, this is serious.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-07-25 03:31:19 UTC
GLSA request filed
Comment 3 Larry the Git Cow gentoo-dev 2023-09-17 05:26:36 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=9c38541fc770d5ef98f0327092ae33c0bab71167

commit 9c38541fc770d5ef98f0327092ae33c0bab71167
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2023-09-17 05:24:21 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-09-17 05:26:26 +0000

    [ GLSA 202309-03 ] GPL Ghostscript: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/904245
    Bug: https://bugs.gentoo.org/910294
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Sam James <sam@gentoo.org>

 glsa-202309-03.xml | 45 +++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 45 insertions(+)