Ubuntu has issued an advisory on August 17: https://ubuntu.com/security/notices/USN-6297-1 Mageia 8 and 9 are also affected.
Source RPM: (none) => ghostscript-10.00.0-6.1.mga9.src.rpmAssignee: bugsquad => nicolas.salgueroCC: (none) => nicolas.salgueroWhiteboard: (none) => MGA9TOO, MGA8TOO
Summary: ghostscript new security issue CVE-2023-38559 => ghostscript new security issues CVE-2023-38559 and CVE-2023-38560
CVE-2023-38560 affects some code not present in ghostscript (pcl)
Summary: ghostscript new security issues CVE-2023-38559 and CVE-2023-38560 => ghostscript new security issue CVE-2023-38559
Blocks: (none) => 32070
Suggested advisory: ======================== The updated packages fix a security vulnerability: Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix). (CVE-2023-36664) A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs. (CVE-2023-38559) References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-36664 https://www.debian.org/security/2023/dsa-5446 https://ubuntu.com/security/notices/USN-6213-1 https://bugs.mageia.org/show_bug.cgi?id=32070 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38559 https://ubuntu.com/security/notices/USN-6297-1 ======================== Updated packages in 8/core/updates_testing: ======================== ghostscript-9.53.3-2.6.mga8 ghostscript-X-9.53.3-2.6.mga8 ghostscript-common-9.53.3-2.6.mga8 ghostscript-doc-9.53.3-2.6.mga8 ghostscript-dvipdf-9.53.3-2.6.mga8 ghostscript-module-X-9.53.3-2.6.mga8 lib(64)gs-devel-9.53.3-2.6.mga8 lib(64)gs9-9.53.3-2.6.mga8 lib(64)ijs-devel-0.35-162.6.mga8 lib(64)ijs1-0.35-162.6.mga8 from SRPM: ghostscript-9.53.3-2.6.mga8.src.rpm Updated packages in 9/core/updates_testing: ======================== ghostscript-10.00.0-6.2.mga9 ghostscript-X-10.00.0-6.2.mga9 ghostscript-common-10.00.0-6.2.mga9 ghostscript-doc-10.00.0-6.2.mga9 ghostscript-dvipdf-10.00.0-6.2.mga9 ghostscript-module-X-10.00.0-6.2.mga9 lib(64)gs10-10.00.0-6.2.mga9 lib(64)gs-devel-10.00.0-6.2.mga9 lib(64)ijs1-0.35-173.1.mga9 lib(64)ijs-devel-0.35-173.1.mga9 from SRPM: ghostscript-10.00.0-6.2.mga9.src.rpm
Status: NEW => ASSIGNEDVersion: Cauldron => 9Whiteboard: MGA9TOO, MGA8TOO => MGA8TOO
*** Bug 32070 has been marked as a duplicate of this bug. ***
CC: (none) => luigiwalser
Assignee: nicolas.salguero => qa-bugs
CC: (none) => mageia
MGA8-64 Xfce on Acer Aspire 5253 No installation issues. Ref bug 31758 Comment 5: Used okular and the gs command to display some device's pdf manual and all worked OK.
CC: (none) => herman.viaeneWhiteboard: MGA8TOO => MGA8TOO MGA8-64-OK
Mageia9, x86_64 qarepo could not find the last two packages in the list. The chosen mirror contained the next version, 2. Retried with the corrected package names and all was well. lib64ijs-devel-0.35-173.2.mga9.x86_64.rpm lib64ijs1-0.35-173.2.mga9.x86_64.rpm Ran MageiaUpdate. $ lilypond input_regression_les-nereides.ly GNU LilyPond 2.24.1 (running Guile 2.2) Processing `input_regression_les-nereides.ly' Parsing... Interpreting music... Preprocessing graphical objects... Finding the ideal number of pages... Fitting music on 1 page... Drawing systems... Converting to `input_regression_les-nereides.pdf'... Success: compilation successfully completed Viewed the resulting PDF file in okular and gs - it displayed a few bars of a musical score. Printed that from the file menu in okular. Viewed an encapsulated postscript file with gs then printed it via CUPS. $ lpr -Pokda abc-0.ps That delivered a sheet of postal labels in the Gemelli font. This looks good for Mageia9.
Whiteboard: MGA8TOO MGA8-64-OK => MGA8TOO MGA8-64-OK MGA9-64-OKCC: (none) => tarazed25
Oops ! You are right: I forgot to increase the sub release number in my comment 2. Sorry!
Validating. Advisory in comment 2.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
CC: (none) => davidwhodginsKeywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2023-0260.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED