Ubuntu Security Notice USN-2697-1
30th July, 2015
ghostscript vulnerability
A security issue affects these releases of Ubuntu and its
derivatives:
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary
Ghostscript could be made to crash or run programs if it processed a
specially crafted file.
Software description
- ghostscript
– PostScript and PDF interpreter
Details
William Robinet and Stefan Cornelius discovered that Ghostscript did not
correctly handle certain Postscript files. If a user or automated system
were tricked into opening a specially crafted file, an attacker could cause
a denial of service or possibly execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following
package version:
- Ubuntu 15.04:
-
libgs9
9.15+dfsg-0ubuntu2.1
- Ubuntu 14.04 LTS:
-
libgs9
9.10~dfsg-0ubuntu10.4
- Ubuntu 12.04 LTS:
-
libgs9
9.05~dfsg-0ubuntu4.3
To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.
In general, a standard system update will make all the necessary changes.