| Errata ID | 534 |
|---|---|
| Date | 2018-10-24 |
| Source package | ghostscript |
| Fixed in version | 9.06~dfsg-2+deb8u11 |
| Description | This update addresses the following issues: * Ghostscript allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183. (CVE-2018-17961) * Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object. (CVE-2018-18073) * Ghostscript allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator. (CVE-2018-18284) |
| Additional notes | |
| CVE ID | CVE-2018-17961 CVE-2018-18073 CVE-2018-18284 |
| UCS Bug number | #48041 |
