Debian Security Advisory
DSA-3326-1 ghostscript -- security update
- Date Reported:
- 02 Aug 2015
- Affected Packages:
- ghostscript
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 793489.
In Mitre's CVE dictionary: CVE-2015-3228. - More information:
-
William Robinet and Stefan Cornelius discovered an integer overflow in Ghostscript, the GPL PostScript/PDF interpreter, which may result in denial of service or potentially execution of arbitrary code if a specially crafted file is opened.
For the oldstable distribution (wheezy), this problem has been fixed in version 9.05~dfsg-6.3+deb7u2.
For the stable distribution (jessie), this problem has been fixed in version 9.06~dfsg-2+deb8u1.
For the testing distribution (stretch), this problem has been fixed in version 9.15~dfsg-1.
For the unstable distribution (sid), this problem has been fixed in version 9.15~dfsg-1.
We recommend that you upgrade your ghostscript packages.