Ubuntu

“ghostscript” 8.71.dfsg.2-0ubuntu7.1 source package in Ubuntu

Changelog

ghostscript (8.71.dfsg.2-0ubuntu7.1) maverick-security; urgency=low

  * SECURITY UPDATE: integer overflows via integer multiplication for
    memory allocation
    - debian/patches/CVE-2008-352x.dpatch: introduce new size-checked
      allocation functions and use them in:
      * jasper/src/libjasper/base/{jas_cm.c,jas_icc.c,jas_image.c,
        jas_malloc.c,jas_seq.c}
      * jasper/src/libjasper/bmp/bmp_dec.c
      * jasper/src/libjasper/include/jasper/jas_malloc.h
      * jasper/src/libjasper/jp2/{jp2_cod.c,jp2_dec.c,jp2_enc.c}
      * jasper/src/libjasper/jpc/{jpc_cs.c,jpc_dec.c,jpc_enc.c,jpc_mqdec.c,
        jpc_mqenc.c,jpc_qmfb.c,jpc_t1enc.c,jpc_t2cod.c,jpc_t2dec.c,
        jpc_t2enc.c,jpc_tagtree.c,jpc_util.c}
      * jasper/src/libjasper/mif/mif_cod.c
    - CVE-2008-3520
  * SECURITY UPDATE: buffer overflow via vsprintf in jas_stream_printf()
    - debian/patches/CVE-2008-352x.dpatch: use vsnprintf() in
      jasper/src/libjasper/base/jas_stream.c
    - CVE-2008-3522
  * SECURITY UPDATE: denial of service and possible code execution via
    heap-based buffer overflows.
    - debian/patches/CVE-2011-451x.dpatch: validate compparms->numrlvls
      and allocate proper size in jasper/src/libjasper/jpc/jpc_cs.c.
    - CVE-2011-4516
    - CVE-2011-4517
 -- Marc Deslauriers <email address hidden>   Tue, 20 Dec 2011 14:09:50 -0500

Upload details

Uploaded by:
Marc Deslauriers on 2011-12-20
Uploaded to:
Maverick
Original maintainer:
Ubuntu Developers
Component:
main
Architectures:
any
Section:
text
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size MD5 Checksum
ghostscript_8.71.dfsg.2.orig.tar.gz 22.6 MiB 8258c7336e61f322da4a4cd2b1a30000
ghostscript_8.71.dfsg.2-0ubuntu7.1.diff.gz 78.9 KiB ff4329a9893a7f156a57bf0dbca8ff17
ghostscript_8.71.dfsg.2-0ubuntu7.1.dsc 2.4 KiB 6d17c751ba77b222127c41a18c6033f8

Binary packages built by this source

ghostscript: The GPL Ghostscript PostScript/PDF interpreter

 Ghostscript is used for PostScript/PDF preview and printing. Usually as
 a back-end to a program such as ghostview, it can display PostScript and PDF
 documents in an X11 environment.
 .
 Furthermore, it can render PostScript and PDF files as graphics to be printed
 on non-PostScript printers. Supported printers include common
 dot-matrix, inkjet and laser models.
 .
 Package gsfonts contains a set of standard fonts for Ghostscript.

ghostscript-cups: The GPL Ghostscript PostScript/PDF interpreter - CUPS filters

 Ghostscript is used for PostScript/PDF preview and printing. Usually as
 a back-end to a program such as ghostview, it can display PostScript and PDF
 documents in an X11 environment.
 .
 This package contains the CUPS filters, drivers, and PPDs which come with
 Ghostscript. To not make Ghostscript itself requiring CUPS these files are
 in a separate package now.

ghostscript-doc: The GPL Ghostscript PostScript/PDF interpreter - Documentation

 Ghostscript is used for PostScript/PDF preview and printing. Usually as
 a back-end to a program such as ghostview, it can display PostScript and PDF
 documents in an X11 environment.
 .
 This package contains the documentation of Ghostscript. As this documentation
 is only interesting for printer driver developers or advanced users, it is
 in this separate package which can be left out in space-restricted
 installations, like for example live CDs.

ghostscript-x: The GPL Ghostscript PostScript/PDF interpreter - X Display support

 Ghostscript is used for PostScript/PDF preview and printing. Usually as
 a back-end to a program such as ghostview, it can display PostScript and PDF
 documents in an X11 environment.
 .
 This package contains the Ghostscript output device for X11. It is in
 a separate package to allow the main package (ghostscript) to be installed
 on X-less servers.

gs: Transitional package

 This dummy package is provided for a smooth transition from the
 previous gs package (the package name has been changed to ghostscript).
 It may safely be removed after installation.

gs-aladdin: Transitional package

 This dummy package is provided for a smooth transition from the
 previous gs-aladdin package (the package is replaced by ghostscript).
 It may safely be removed after installation.

gs-common: Dummy package depending on ghostscript

 This dummy package is provided for a smooth transition from the
 previous gs-.../gs-common combo (the packages are replaced by ghostscript).
 It may safely be removed after installation.

gs-esp: Transitional package

 This dummy package is provided for a smooth transition from the
 previous gs-esp package (the package is replaced by ghostscript).
 It may safely be removed after installation.

gs-esp-x: Transitional package

 This dummy package is provided for a smooth transition from the
 previous gs-esp-x package (the package is replaced by ghostscript-x).
 It may safely be removed after installation.

gs-gpl: Transitional package

 This dummy package is provided for a smooth transition from the
 previous gs-gpl package (the package is replaced by ghostscript).
 It may safely be removed after installation.

libgs-dev: The Ghostscript PostScript Library - Development Files

 Ghostscript is used for PostScript/PDF preview and printing. Usually as
 a back-end to a program such as ghostview, it can display PostScript and PDF
 documents in an X11 environment.
 .
 This package provides the development files for the Ghostscript library
 which makes the facilities of Ghostscript available to applications.

libgs-esp-dev: Transitional package

 This dummy package is provided for a smooth transition from the
 previous libgs-esp-dev package (the package is replaced by libgs-dev).
 It may safely be removed after installation.

libgs8: The Ghostscript PostScript/PDF interpreter Library

 Ghostscript is used for PostScript/PDF preview and printing. Usually as
 a back-end to a program such as ghostview, it can display PostScript and PDF
 documents in an X11 environment.
 .
 This package provides the Ghostscript library which makes the
 facilities of Ghostscript available to applications.