-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 24 Aug 2024 21:29:52 +0200 Source: ghostscript Binary: ghostscript ghostscript-dbgsym ghostscript-x libgs-dev libgs10 libgs10-dbgsym Architecture: mips64el Version: 10.0.0~dfsg-11+deb12u5 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Salvatore Bonaccorso Description: ghostscript - interpreter for the PostScript language and for PDF ghostscript-x - transitional package for ghostscript libgs-dev - interpreter for the PostScript language and for PDF - Development libgs10 - interpreter for the PostScript language and for PDF - Library Changes: ghostscript (10.0.0~dfsg-11+deb12u5) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * review printing of pointers (CVE-2024-29508) * Fix compiler warning in optimised build * Coverity IDs 414141 & 414145 * Don't allow PDF files with bad Filters to overflow the debug buffer (CVE-2024-29506) * Don't use strlen on passwords (CVE-2024-29509) * Bounds checks when using CIDFont related params (CVE-2024-29507) Checksums-Sha1: 125f16692bcbb7d8d9a10875b899d5d95fd7bb9e 6256 ghostscript-dbgsym_10.0.0~dfsg-11+deb12u5_mips64el.deb acc567a508e0152f08c869013d24061336e3c695 28052 ghostscript-x_10.0.0~dfsg-11+deb12u5_mips64el.deb 563db333d2a791361b6b06c3ed9aeaf72a672052 11865 ghostscript_10.0.0~dfsg-11+deb12u5_mips64el-buildd.buildinfo 2af1336ff22283b1563e4aa3e941625658295adc 57404 ghostscript_10.0.0~dfsg-11+deb12u5_mips64el.deb 51ad6dc2abbd6c5b4decb64a891d909c5cf67114 39580 libgs-dev_10.0.0~dfsg-11+deb12u5_mips64el.deb d537a4d6dcf3cca5cd0cd00e58c3fa239eecdaa4 9850292 libgs10-dbgsym_10.0.0~dfsg-11+deb12u5_mips64el.deb 22a2d08ab525ab6514ebc6444764b653bfba0d64 2218624 libgs10_10.0.0~dfsg-11+deb12u5_mips64el.deb Checksums-Sha256: 4392eedb72a3e9e1be71ed5f3fc00efda2fd787826127964179206b75d554ad5 6256 ghostscript-dbgsym_10.0.0~dfsg-11+deb12u5_mips64el.deb b3c7e4a085cb4bd7ea3cdcae514c0ab5c5da7b9cc980e4463f93bb8cae9a935c 28052 ghostscript-x_10.0.0~dfsg-11+deb12u5_mips64el.deb 300f072520caa969f38465d6c680b03656a29cb387c92cc8cbc671d3b1a9f6e1 11865 ghostscript_10.0.0~dfsg-11+deb12u5_mips64el-buildd.buildinfo f514280cf592f34b58fa6aff5864fb71113aaa5cb046c8e64ec93d9b8304e3d1 57404 ghostscript_10.0.0~dfsg-11+deb12u5_mips64el.deb de6392d1f58f16f778c2172c217c1b0cf3924a0a81c0079b143ba43b466ba9fa 39580 libgs-dev_10.0.0~dfsg-11+deb12u5_mips64el.deb 1cb28b67bbd8675462dffa4160ec4ddcab1c5a39107ee746309832fa973f6723 9850292 libgs10-dbgsym_10.0.0~dfsg-11+deb12u5_mips64el.deb bf18708680c5c3ca42b46aa40ce44f40703888de3b87af6bb6aef00169f6e929 2218624 libgs10_10.0.0~dfsg-11+deb12u5_mips64el.deb Files: 243ec11c457c9f012902a0d5d7a1b28a 6256 debug optional ghostscript-dbgsym_10.0.0~dfsg-11+deb12u5_mips64el.deb 803617f20a69a96de3b62c6e5fdc7437 28052 oldlibs optional ghostscript-x_10.0.0~dfsg-11+deb12u5_mips64el.deb b6e25145e32fd55c4e128221020b8af4 11865 text optional ghostscript_10.0.0~dfsg-11+deb12u5_mips64el-buildd.buildinfo cf478e3edf0fd7b84cd7137b8a34d761 57404 text optional ghostscript_10.0.0~dfsg-11+deb12u5_mips64el.deb 53f37af6c7f7508e0241bc548309cbc7 39580 libdevel optional libgs-dev_10.0.0~dfsg-11+deb12u5_mips64el.deb 45d2bcd4438d995b03acbc683cf74da3 9850292 debug optional libgs10-dbgsym_10.0.0~dfsg-11+deb12u5_mips64el.deb b3e13c9bbf84430b59404c752983ab3d 2218624 libs optional libgs10_10.0.0~dfsg-11+deb12u5_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEuQAPGkYIXAAfq7z1C2Vm2FYVKKAFAmbLNXsACgkQC2Vm2FYV KKBqmg//a5uPIUED3DwsGZheXrxlHosLaf5pUkzrKPxMZMsmxhOUvJsYcOZwUuNO Y9taeFlb53Q9Ho7haDNuHq+63uGNuG2heYVgYGNuFmV/sBrkiObxE/zrLtOdulMa bLL1qNS2YMGzl+eqsNn+dtDx3iGnNTguwgG/CXPvP/3nBMMKHL+LOiVnKN+BRYWH Lk09jVORxm+QvLaY6CZv/30PDoNgvb39mDuuQtOtu1WClWW+xB1i6RJke/4w0lfp N15aI2qo0hLLe4uNW8UbSDOzvpb//KAe/48VSzTcMQ63MkpoFVAVsMrwIKDnDXbL phnhLyu8BkgZrWqTUqcX1K+5/aNBbg4axZfZwUOJ25h/83r6hEBrivBse6ObRq9H 7d2hPbLubVSeVUADNQ/yC/mkXvN2oAoaiJuMLfvzmj5xz3+OSANFG++62vDW6PYe W4jFpundgMGezctGtbHfIgZnkzHAzT2lZFzl2VM2Uwgp0dbfFJZl3Y7t45z86Rou dTrQx2wgJA70vXYA0ySdflYWuc/9Vy/l0adBxVnlyFVI3wNJujF/0z5xvNIqXFnN aDSuWMc2XSIPzjunjQ3sciE4gpeJTlwfvT5n7GtoDjEL+dLoxQ//dZlFi6AboORm fjfoi2rS57TwsswGflTuj0it+3qvNXqGoL7FrrrJO2/tIQ3SSmg= =ZMXv -----END PGP SIGNATURE-----