Hide Forgot
.initialize_dsc_parser doesn't validate the parameter is a dict type before using it. This is a security issue, because it can be abused to escape the -dSAFER sandbox. This allows a Denial of Service, arbitrary code execution. Upstream bug : - Bug 697190 - .initialize_dsc_parser doesn't validate the parameter is a dict type before using it. http://bugs.ghostscript.com/show_bug.cgi?id=697190 Upstream patch : - DSC parser - validate parameters http://git.ghostscript.com/?p=ghostpdl.git;h=875a0095f37626a721c7ff57d606a0f95af03913 Reference : http://seclists.org/oss-sec/2016/q4/37
Created ghostscript tracking bugs for this issue: Affects: fedora-all [bug 1390489]
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2017:0014 https://rhn.redhat.com/errata/RHSA-2017-0014.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:0013 https://rhn.redhat.com/errata/RHSA-2017-0013.html