Your submission was sent successfully! Close

CVE-2019-25059

Published: 25 April 2022

Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.

Notes

AuthorNote
mdeslaur
incomplete fix for CVE-2019-6116 and CVE-2019-3839
third commit is probably unnecessary and is not in focal+
Priority

Medium

CVSS 3 base score: 7.8

Status

Package Release Status
ghostscript
Launchpad, Ubuntu, Debian
bionic
Released (9.26~dfsg+0-0ubuntu0.18.04.16)
focal Not vulnerable
(9.50~dfsg-5ubuntu4)
impish Not vulnerable
(9.54.0~dfsg1-0ubuntu2)
jammy Not vulnerable
(9.55.0~dfsg1-0ubuntu5)
upstream Needed

xenial
Released (9.26~dfsg+0-0ubuntu0.16.04.14+esm3)
Patches:
upstream: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=430e219ea17a2650577d70021399c4ead05869e0
upstream: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=fe316c21cb1c9a192da58158155a56f46f1f753a
upstream: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=a9e0b6839b44822f2b511d4595535869096a2ff1 (probably optional)