USN-7473-1: Ghostscript vulnerability
USN-7473-1: Ghostscript vulnerability
1 May 2025
Ghostscript could be made to crash, run programs, or read files if it opened a specially crafted file.
Releases
- Ubuntu 24.10
- Ubuntu 24.04 LTS
Packages
ghostscript - PostScript and PDF interpreter
Details
It was discovered that Ghostscript incorrectly handled parsing certain PS
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly bypass file path validation.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
- ghostscript - 10.03.1~dfsg1-0ubuntu2.3
- libgs10 - 10.03.1~dfsg1-0ubuntu2.3
Ubuntu 24.04 - ghostscript - 10.02.1~dfsg1-0ubuntu7.6
- libgs10 - 10.02.1~dfsg1-0ubuntu7.6
In general, a standard system update will make all the necessary changes.