|
|
|
|
| |
| GhostScript makes use of mktemp instead of mkstemp to create temp files; it also uses improper LD_RUN_PATH values, causing it to search for libraries in the current directory. Both these unsafe security practices expose the application to several possible attacks. |
| |
Credit:
The information has been provided by RedHat Bugzilla, Caldera Support Info, Debian security announce, Linux Mandrake Security Team and Conectiva Secure.
|
| |
Vulnerable systems:
Red Hat Linux 5.0 - i386, Alpha, Sparc
Red Hat Linux 5.1 - i386, Alpha, Sparc
Red Hat Linux 5.2 - i386, Alpha, Sparc
Red Hat Linux 6.0 - i386, Alpha, Sparc
Red Hat Linux 6.1 - i386, Alpha, Sparc
Red Hat Linux 6.2 - i386, Alpha, Sparc
Red Hat Linux 7.0 - i386
OpenLinux Desktop 2.3
OpenLinux eServer 2.3
OpenLinux eBuilder for ECential 3.0
OpenLinux eDesktop 2.4
Debian GNU/Linux 2.2
Mandrake Linux 6.0
Mandrake Linux 6.1
Mandrake Linux 7.0
Mandrake Linux 7.1
Mandrake Linux 7.2
Conectiva 4.0
Conectiva 4.0es
Conectiva 4.1
Conectiva 4.2
Conectiva 5.0
Conectiva prg gr?ficos
Conectiva eCommerce, 5.1
GhostScript makes use of mktemp to create temp files, which is an insecure and predictable approach. It has now been patched to use mkstemp, which avoids the race condition on the name.
It also uses improper LD_RUN_PATH values, causing GhostScript to search for libraries to load in current directories.
Solution (RedHat):
For each RPM for your particular architecture, run:
rpm -Fvh [filename]
Where filename is the name of the RPM.
Patch:
Red Hat Linux 5.2:
Alpha:
ftp://updates.redhat.com/5.2/alpha/ghostscript-4.03-2.alpha.rpm
Sparc:
ftp://updates.redhat.com/5.2/sparc/ghostscript-4.03-2.sparc.rpm
i386:
ftp://updates.redhat.com/5.2/i386/ghostscript-4.03-2.i386.rpm
Sources:
ftp://updates.redhat.com/5.2/SRPMS/ghostscript-4.03-2.src.rpm
Red Hat Linux 6.2:
Alpha:
ftp://updates.redhat.com/6.2/alpha/ghostscript-5.50-8_6.x.alpha.rpm
Sparc:
ftp://updates.redhat.com/6.2/sparc/ghostscript-5.50-8_6.x.sparc.rpm
i386:
ftp://updates.redhat.com/6.2/i386/ghostscript-5.50-8_6.x.i386.rpm
Sources:
ftp://updates.redhat.com/6.2/SRPMS/ghostscript-5.50-8_6.x.src.rpm
Red Hat Linux 7.0:
i386:
ftp://updates.redhat.com/7.0/i386/ghostscript-5.50-8.i386.rpm
Sources:
ftp://updates.redhat.com/7.0/SRPMS/ghostscript-5.50-8.src.rpm
OpenLinux Desktop 2.3:
The upgrade packages can be found on Caldera's FTP site at:
ftp://ftp.calderasystems.com/pub/updates/OpenLinux/2.3/current/RPMS/
The corresponding source code package can be found at:
ftp://ftp.calderasystems.com/pub/updates/OpenLinux/2.3/current/SRPMS
RPMS/ghostscript-5.10-16.i386.rpm
RPMS/ghostscript-doc-5.10-16.i386.rpm
RPMS/ghostscript-fonts-5.10-16.i386.rpm
SRPMS/ghostscript-5.10-16.src.rpm
OpenLinux eServer 2.3 and OpenLinux eBuilder for ECential 3.0:
The upgrade packages can be found on Caldera's FTP site at:
ftp://ftp.calderasystems.com/pub/updates/eServer/2.3/current/RPMS/
The corresponding source code package can be found at:
ftp://ftp.calderasystems.com/pub/updates/eServer/2.3/current/SRPMS
RPMS/ghostscript-5.10-16.i386.rpm
RPMS/ghostscript-doc-5.10-16.i386.rpm
RPMS/ghostscript-fonts-5.10-16.i386.rpm
SRPMS/ghostscript-5.10-16.src.rpm
OpenLinux eDesktop 2.4:
The upgrade packages can be found on Caldera's FTP site at:
ftp://ftp.calderasystems.com/pub/updates/eDesktop/2.4/current/RPMS/
The corresponding source code package can be found at:
ftp://ftp.calderasystems.com/pub/updates/eDesktop/2.4/current/SRPMS
RPMS/ghostscript-5.10-16.i386.rpm
RPMS/ghostscript-doc-5.10-16.i386.rpm
RPMS/ghostscript-fonts-5.10-16.i386.rpm
SRPMS/ghostscript-5.10-16.src.rpm
Debian GNU/Linux 2.2 alias potato
Potato was released for Alpha, ARM, i386, M68k, PowerPC and Sparc.
Source archives:
http://security.debian.org/dists/stable/updates/main/source/gs_5.10-10.1.diff.gz
http://security.debian.org/dists/stable/updates/main/source/gs_5.10-10.1.dsc
http://security.debian.org/dists/stable/updates/main/source/gs_5.10.orig.tar.gz
Alpha architecture:
http://security.debian.org/dists/stable/updates/main/binary-alpha/gs_5.10-10.1_alpha.deb
ARM architecture:
http://security.debian.org/dists/stable/updates/main/binary-arm/gs_5.10-10.1_arm.deb
Intel ia32 architecture:
http://security.debian.org/dists/stable/updates/main/binary-i386/gs_5.10-10.1_i386.deb
Motorola 680x0 architecture:
http://security.debian.org/dists/stable/updates/main/binary-m68k/gs_5.10-10.1_m68k.deb
PowerPC architecture:
http://security.debian.org/dists/stable/updates/main/binary-powerpc/gs_5.10-10.1_powerpc.deb
Sun Sparc architecture:
http://security.debian.org/dists/stable/updates/main/binary-sparc/gs_5.10-10.1_sparc.deb
Linux-Mandrake 6.0:
6.0/RPMS/ghostscript-5.10-10.1mdk.i586.rpm
6.0/SRPMS/ghostscript-5.10-10.1mdk.src.rpm
Linux-Mandrake 6.1:
6.1/RPMS/ghostscript-5.10-10.1mdk.i586.rpm
6.1/SRPMS/ghostscript-5.10-10.1mdk.src.rpm
Linux-Mandrake 7.0:
7.0/RPMS/ghostscript-5.10-17.1mdk.i586.rpm
7.0/RPMS/ghostscript-Both-5.10-17.1mdk.i586.rpm
7.0/RPMS/ghostscript-PrintOnly-5.10-17.1mdk.i586.rpm
7.0/RPMS/ghostscript-SVGALIB-5.10-17.1mdk.i586.rpm
7.0/RPMS/ghostscript-X-5.10-17.1mdk.i586.rpm
7.0/SRPMS/ghostscript-5.10-17.1mdk.src.rpm
Linux-Mandrake 7.1:
7.1/RPMS/ghostscript-5.50-9.1mdk.i586.rpm
7.1/RPMS/ghostscript-Both-5.50-9.1mdk.i586.rpm
7.1/RPMS/ghostscript-PrintOnly-5.50-9.1mdk.i586.rpm
7.1/RPMS/ghostscript-SVGALIB-5.50-9.1mdk.i586.rpm
7.1/RPMS/ghostscript-X-5.50-9.1mdk.i586.rpm
7.1/SRPMS/ghostscript-5.50-9.1mdk.src.rpm
Linux-Mandrake 7.2:
7.2/RPMS/ghostscript-5.50-35.1mdk.i586.rpm
7.2/RPMS/ghostscript-module-SVGALIB-5.50-35.1mdk.i586.rpm
7.2/RPMS/ghostscript-module-X-5.50-35.1mdk.i586.rpm
7.2/RPMS/ghostscript-utils-5.50-35.1mdk.i586.rpm
7.2/SRPMS/ghostscript-5.50-35.1mdk.src.rpm
Conectiva:
ftp://atualizacoes.conectiva.com.br/4.0/SRPMS/ghostscript-5.10-12cl.src.rpm
ftp://atualizacoes.conectiva.com.br/4.0/i386/ghostscript-5.10-12cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.0es/SRPMS/ghostscript-5.10-12cl.src.rpm
ftp://atualizacoes.conectiva.com.br/4.0es/i386/ghostscript-5.10-12cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.1/SRPMS/ghostscript-5.10-12cl.src.rpm
ftp://atualizacoes.conectiva.com.br/4.1/i386/ghostscript-5.10-12cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.2/SRPMS/ghostscript-5.10-12cl.src.rpm
ftp://atualizacoes.conectiva.com.br/4.2/i386/ghostscript-5.10-12cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/SRPMS/ghostscript-5.10-12cl.src.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/ghostscript-5.10-12cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/SRPMS/ghostscript-5.10-12cl.src.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/ghostscript-5.10-12cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/SRPMS/ghostscript-5.10-12cl.src.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/i386/ghostscript-5.10-12cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/graficas/SRPMS/ghostscript-5.10-12cl.src.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/graficas/i386/ghostscript-5.10-12cl.i386.rpm
|
|
|
|
|