ALAS-2025-1978安全公告
公告发布日期:2025-05-12
公告更新日期:2025-05-12
严重程度:重要
相关CVE:
- CVE-2024-46951
- CVE-2024-46953
- CVE-2024-46956
问题概述
CVE-2024-46951: PS解释器 - 检查Pattern Implementation的类型 参考链接:
- https://bugs.ghostscript.com/show_bug.cgi?id=707991
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f49812186baa7d1362880673408a6fbe8719b4f8
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=ada21374f0c90cc3acf7ce0e96302394560c7aee (ghostpdl-10.04.0)
CVE-2024-46953: 检查验证格式字符串时的溢出问题 参考链接:
- https://bugs.ghostscript.com/show_bug.cgi?id=707793
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=1f21a45df0fa3abec4cff12951022b192dda3c00
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=294a3755e33f453dd92e2a7c4cfceb087ac09d6a (ghostpdl-10.04.0)
CVE-2024-46956: PostScript解释器 - 修复缓冲区长度检查 参考链接:
- https://bugs.ghostscript.com/show_bug.cgi?id=707895
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f4151f12db32cd3ed26c24327de714bf2c3ed6ca
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=ea69a1388245ad959d31c272b5ba66d40cebba2c (ghostpdl-10.04.0)
受影响软件包
- ghostscript
问题修复
运行以下命令更新系统:
|
|
或
|
|
新软件包版本
i686架构:
- ghostscript-debuginfo-8.70-24.35.amzn1.i686
- ghostscript-devel-8.70-24.35.amzn1.i686
- ghostscript-doc-8.70-24.35.amzn1.i686
- ghostscript-8.70-24.35.amzn1.i686
源代码包:
- ghostscript-8.70-24.35.amzn1.src
x86_64架构:
- ghostscript-devel-8.70-24.35.amzn1.x86_64
- ghostscript-doc-8.70-24.35.amzn1.x86_64
- ghostscript-debuginfo-8.70-24.35.amzn1.x86_64
- ghostscript-8.70-24.35.amzn1.x86_64
附加参考
- Red Hat:CVE-2024-46951, CVE-2024-46953, CVE-2024-46956
- Mitre:CVE-2024-46951, CVE-2024-46953, CVE-2024-46956