==========================================================================
Ubuntu Security Notice USN-7378-1
March 27, 2025

ghostscript vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in Ghostscript.

Software Description:
- ghostscript: PostScript and PDF interpreter

Details:

It was discovered that Ghostscript incorrectly serialized DollarBlend in
certain fonts. An attacker could use this issue to cause Ghostscript to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2025-27830)

It was discovered that Ghostscript incorrectly handled the DOCXWRITE
TXTWRITE device. An attacker could use this issue to cause Ghostscript to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and
Ubuntu 24.10. (CVE-2025-27831)

It was discovered that Ghostscript incorrectly handled the NPDL device. An
attacker could use this issue to cause Ghostscript to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-27832)

It was discovered that Ghostscript incorrectly handled certain long TTF
file names. An attacker could use this issue to cause Ghostscript to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 24.10.
(CVE-2025-27833)

It was discovered that Ghostscript incorrectly handled oversized Type 4
functions in certain PDF documents. An attacker could use this issue to
cause Ghostscript to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu
24.04 LTS, and Ubuntu 24.10. (CVE-2025-27834)

It was discovered that Ghostscript incorrectly handled converting certain
glyphs to Unicode. An attacker could use this issue to cause Ghostscript to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2025-27835)

It was discovered that Ghostscript incorrectly handled the BJ10V device. An
attacker could use this issue to cause Ghostscript to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-27836)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
  ghostscript                     10.03.1~dfsg1-0ubuntu2.2
  libgs10                         10.03.1~dfsg1-0ubuntu2.2

Ubuntu 24.04 LTS
  ghostscript                     10.02.1~dfsg1-0ubuntu7.5
  libgs10                         10.02.1~dfsg1-0ubuntu7.5

Ubuntu 22.04 LTS
  ghostscript                     9.55.0~dfsg1-0ubuntu5.11
  libgs9                          9.55.0~dfsg1-0ubuntu5.11

Ubuntu 20.04 LTS
  ghostscript                     9.50~dfsg-5ubuntu4.15
  libgs9                          9.50~dfsg-5ubuntu4.15

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-7378-1
  CVE-2025-27830, CVE-2025-27831, CVE-2025-27832, CVE-2025-27833,
  CVE-2025-27834, CVE-2025-27835, CVE-2025-27836

Package Information:
  https://launchpad.net/ubuntu/+source/ghostscript/10.03.1~dfsg1-0ubuntu2.2
  https://launchpad.net/ubuntu/+source/ghostscript/10.02.1~dfsg1-0ubuntu7.5
  https://launchpad.net/ubuntu/+source/ghostscript/9.55.0~dfsg1-0ubuntu5.11
  https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.15

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature



Reply via email to