Re: [OE-core] [PATCH] ghostscript: CVE-2019-14869

2019-11-21 Thread Ross Burton
On 21/11/2019 15:28, Stefan Ghinea wrote: file://CVE-2019-14811-0001.patch \ file://CVE-2019-14817-0001.patch \ file://CVE-2019-14817-0002.patch \ +file://CVE-2019-14869-0001.patch \ + " Parsing recipes...ERROR:

[OE-core] [PATCH] ghostscript: CVE-2019-14869

2019-11-21 Thread Stefan Ghinea
A flaw was found in all versions of ghostscript 9.x before 9.28, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could