SUSE-SU-2017:1138-1

Advisory lineage Upstream: 5 Downstream: 0
Published: 28 Apr 2017, 18:55
Last modified:04 Feb 2026, 02:27

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

28 Apr 2017, 18:55
Published
Vulnerability first disclosed
04 Feb 2026, 02:27
Last Modified
Vulnerability information updated

Description

Security update for ghostscript This update for ghostscript fixes the following security vulnerabilities: CVE-2017-8291: A remote command execution and a -dSAFER bypass via a crafted .eps document were exploited in the wild. (bsc#1036453) CVE-2016-9601: An integer overflow in the bundled jbig2dec library could have been misused to cause a Denial-of-Service. (bsc#1018128) CVE-2016-10220: A NULL pointer dereference in the PDF Transparency module allowed remote attackers to cause a Denial-of-Service. (bsc#1032120) CVE-2017-5951: A NULL pointer dereference allowed remote attackers to cause a denial of service via a crafted PostScript document. (bsc#1032114) CVE-2017-7207: A NULL pointer dereference allowed remote attackers to cause a denial of service via a crafted PostScript document. (bsc#1030263)

Affected Systems

  • suseghostscript&distro=SUSE Linux Enterprise Desktop 12 SP1

    < 9.15-20.1

  • suseghostscript&distro=SUSE Linux Enterprise Desktop 12 SP2

    < 9.15-20.1

  • suseghostscript&distro=SUSE Linux Enterprise Server 12 SP1

    < 9.15-20.1

  • suseghostscript&distro=SUSE Linux Enterprise Server 12 SP2

    < 9.15-20.1

  • suseghostscript&distro=SUSE Linux Enterprise Server for Raspberry Pi 12 SP2

    < 9.15-20.1

  • suseghostscript&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP1

    < 9.15-20.1

  • suseghostscript&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP2

    < 9.15-20.1

  • suseghostscript&distro=SUSE Linux Enterprise Software Development Kit 12 SP1

    < 9.15-20.1

  • suseghostscript&distro=SUSE Linux Enterprise Software Development Kit 12 SP2

    < 9.15-20.1

References (11)