{"affected":[{"ecosystem_specific":{"binaries":[{"ghostscript-devel":"8.62-32.38.1","ghostscript-ijs-devel":"8.62-32.38.1","libgimpprint-devel":"4.2.7-32.38.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP4","name":"ghostscript-library","purl":"pkg:rpm/suse/ghostscript-library&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.62-32.38.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ghostscript-fonts-other":"8.62-32.38.1","ghostscript-fonts-rus":"8.62-32.38.1","ghostscript-fonts-std":"8.62-32.38.1","ghostscript-library":"8.62-32.38.1","ghostscript-omni":"8.62-32.38.1","ghostscript-x11":"8.62-32.38.1","libgimpprint":"4.2.7-32.38.1"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud 5","name":"ghostscript-library","purl":"pkg:rpm/suse/ghostscript-library&distro=SUSE%20OpenStack%20Cloud%205"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.62-32.38.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ghostscript-fonts-other":"8.62-32.38.1","ghostscript-fonts-rus":"8.62-32.38.1","ghostscript-fonts-std":"8.62-32.38.1","ghostscript-library":"8.62-32.38.1","ghostscript-omni":"8.62-32.38.1","ghostscript-x11":"8.62-32.38.1","libgimpprint":"4.2.7-32.38.1"}]},"package":{"ecosystem":"SUSE:Manager 2.1","name":"ghostscript-library","purl":"pkg:rpm/suse/ghostscript-library&distro=SUSE%20Manager%202.1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.62-32.38.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ghostscript-fonts-other":"8.62-32.38.1","ghostscript-fonts-rus":"8.62-32.38.1","ghostscript-fonts-std":"8.62-32.38.1","ghostscript-library":"8.62-32.38.1","ghostscript-omni":"8.62-32.38.1","ghostscript-x11":"8.62-32.38.1","libgimpprint":"4.2.7-32.38.1"}]},"package":{"ecosystem":"SUSE:Manager Proxy 2.1","name":"ghostscript-library","purl":"pkg:rpm/suse/ghostscript-library&distro=SUSE%20Manager%20Proxy%202.1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.62-32.38.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ghostscript-fonts-other":"8.62-32.38.1","ghostscript-fonts-rus":"8.62-32.38.1","ghostscript-fonts-std":"8.62-32.38.1","ghostscript-library":"8.62-32.38.1","ghostscript-omni":"8.62-32.38.1","ghostscript-x11":"8.62-32.38.1","libgimpprint":"4.2.7-32.38.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Point of Sale 11 SP3","name":"ghostscript-library","purl":"pkg:rpm/suse/ghostscript-library&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.62-32.38.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ghostscript-fonts-other":"8.62-32.38.1","ghostscript-fonts-rus":"8.62-32.38.1","ghostscript-fonts-std":"8.62-32.38.1","ghostscript-library":"8.62-32.38.1","ghostscript-omni":"8.62-32.38.1","ghostscript-x11":"8.62-32.38.1","libgimpprint":"4.2.7-32.38.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP2-LTSS","name":"ghostscript-library","purl":"pkg:rpm/suse/ghostscript-library&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.62-32.38.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ghostscript-fonts-other":"8.62-32.38.1","ghostscript-fonts-rus":"8.62-32.38.1","ghostscript-fonts-std":"8.62-32.38.1","ghostscript-library":"8.62-32.38.1","ghostscript-omni":"8.62-32.38.1","ghostscript-x11":"8.62-32.38.1","libgimpprint":"4.2.7-32.38.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP3-LTSS","name":"ghostscript-library","purl":"pkg:rpm/suse/ghostscript-library&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.62-32.38.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ghostscript-fonts-other":"8.62-32.38.1","ghostscript-fonts-rus":"8.62-32.38.1","ghostscript-fonts-std":"8.62-32.38.1","ghostscript-library":"8.62-32.38.1","ghostscript-omni":"8.62-32.38.1","ghostscript-x11":"8.62-32.38.1","libgimpprint":"4.2.7-32.38.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP3-TERADATA","name":"ghostscript-library","purl":"pkg:rpm/suse/ghostscript-library&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATA"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.62-32.38.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ghostscript-fonts-other":"8.62-32.38.1","ghostscript-fonts-rus":"8.62-32.38.1","ghostscript-fonts-std":"8.62-32.38.1","ghostscript-library":"8.62-32.38.1","ghostscript-omni":"8.62-32.38.1","ghostscript-x11":"8.62-32.38.1","libgimpprint":"4.2.7-32.38.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP4","name":"ghostscript-library","purl":"pkg:rpm/suse/ghostscript-library&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.62-32.38.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ghostscript-fonts-other":"8.62-32.38.1","ghostscript-fonts-rus":"8.62-32.38.1","ghostscript-fonts-std":"8.62-32.38.1","ghostscript-library":"8.62-32.38.1","ghostscript-omni":"8.62-32.38.1","ghostscript-x11":"8.62-32.38.1","libgimpprint":"4.2.7-32.38.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","name":"ghostscript-library","purl":"pkg:rpm/suse/ghostscript-library&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.62-32.38.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\nThis update for ghostscript-library fixes the following issues:\n\n- Multiple security vulnerabilities have been discovered where ghostscript's\n  '-dsafer' flag did not provide sufficient protection against unintended\n  access to the file system. Thus, a machine that would process a specially\n  crafted Postscript file would potentially leak sensitive information to an\n  attacker. (CVE-2013-5653, CVE-2016-7977, bsc#1001951)\n\n- Insufficient validation of the type of input in .initialize_dsc_parser used\n  to allow remote code execution. (CVE-2016-7979, bsc#1001951)\n\n- An integer overflow in the gs_heap_alloc_bytes function used to allow remote\n  attackers to cause a denial of service (crash) via specially  crafted\n  Postscript files. (CVE-2015-3228, boo#939342)\n\n","id":"SUSE-SU-2016:2493-1","modified":"2016-10-11T13:08:17Z","published":"2016-10-11T13:08:17Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2016/suse-su-20162493-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1001951"},{"type":"REPORT","url":"https://bugzilla.suse.com/939342"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2013-5653"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-3228"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7977"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7979"}],"related":["CVE-2013-5653","CVE-2015-3228","CVE-2016-7977","CVE-2016-7979"],"summary":"Security update for ghostscript-library","upstream":["CVE-2013-5653","CVE-2015-3228","CVE-2016-7977","CVE-2016-7979"]}