-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 10 May 2024 14:34:11 +0200 Source: ghostscript Binary: ghostscript ghostscript-dbgsym ghostscript-x ghostscript-x-dbgsym libgs-dev libgs9 libgs9-dbgsym Architecture: amd64 Version: 9.53.3~dfsg-7+deb11u7 Distribution: bullseye-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Salvatore Bonaccorso Description: ghostscript - interpreter for the PostScript language and for PDF ghostscript-x - interpreter for the PostScript language and for PDF - X11 support libgs-dev - interpreter for the PostScript language and for PDF - Development libgs9 - interpreter for the PostScript language and for PDF - Library Changes: ghostscript (9.53.3~dfsg-7+deb11u7) bullseye-security; urgency=high . * Non-maintainer upload by the Security Team. * In SAFER (default) don't allow eexec seeds other than the Type 1 standard (CVE-2023-52722) * Uniprint device - prevent string configuration changes when SAFER (CVE-2024-29510) * Bug #707691 (CVE-2024-33869) * Bug 707691 part 2 (CVE-2024-33869) * Bug #707686 (CVE-2024-33870) * OPVP device - prevent unsafe parameter change with SAFER (CVE-2024-33871) Checksums-Sha1: 8f108493d13480b2782ddca3c39a71a5d3d3e2a4 5828 ghostscript-dbgsym_9.53.3~dfsg-7+deb11u7_amd64.deb 22c6547db7036e91908f89b64aa7ee911602ded0 100312 ghostscript-x-dbgsym_9.53.3~dfsg-7+deb11u7_amd64.deb 519046b81cb180a7c7626298d184c337d1bb320a 94332 ghostscript-x_9.53.3~dfsg-7+deb11u7_amd64.deb 90eeb2ce7954b31f2826c2947dd23bced3c76bff 11706 ghostscript_9.53.3~dfsg-7+deb11u7_amd64-buildd.buildinfo 8c243ad62cb062daacab93e616f6306e0c6c8192 98468 ghostscript_9.53.3~dfsg-7+deb11u7_amd64.deb 9422c1a7be978dd80da7ef63a57a064500a4ddaf 80444 libgs-dev_9.53.3~dfsg-7+deb11u7_amd64.deb e3caaafc2f0f879713defe8f497166377b151f47 7936228 libgs9-dbgsym_9.53.3~dfsg-7+deb11u7_amd64.deb 41cbf9a082e16e987b1027f9a4455c21c8777820 2244380 libgs9_9.53.3~dfsg-7+deb11u7_amd64.deb Checksums-Sha256: 7eebae100e4d183fed689bcee6fede908e8da258525b386f1397bc38672b5b38 5828 ghostscript-dbgsym_9.53.3~dfsg-7+deb11u7_amd64.deb 268a2b04a5ef626f1c38766a0549b68d97ba0448a78971d4790eac6157c72154 100312 ghostscript-x-dbgsym_9.53.3~dfsg-7+deb11u7_amd64.deb 41acfa25846cd3495e3847249ccdba6d5cdbb124e29979b3466de21c7ed55d82 94332 ghostscript-x_9.53.3~dfsg-7+deb11u7_amd64.deb 6cd432bea315f9fa11936571b14a42a2c33356a0e3caaff8ecb9ef3c0edd7f73 11706 ghostscript_9.53.3~dfsg-7+deb11u7_amd64-buildd.buildinfo a4bb56e66b04470451fa5455f3cbe69c7405d2bde651827de3a60435a47d62bf 98468 ghostscript_9.53.3~dfsg-7+deb11u7_amd64.deb 373f9b0030ea56bfc6027140d1fe700f078d89d89126147bbadfb22136073017 80444 libgs-dev_9.53.3~dfsg-7+deb11u7_amd64.deb 04603830d0d770483b05e4515cb73f6bc2083048370787abc1f460af6ef74216 7936228 libgs9-dbgsym_9.53.3~dfsg-7+deb11u7_amd64.deb 36c6c263d74840f684cbbe2ff28b59e86240e286d87a4dfba4d215aae000808f 2244380 libgs9_9.53.3~dfsg-7+deb11u7_amd64.deb Files: 74275c9756a031620e1c919166b25b76 5828 debug optional ghostscript-dbgsym_9.53.3~dfsg-7+deb11u7_amd64.deb 9f724180ccdc58dee32f65a2fbcce6f4 100312 debug optional ghostscript-x-dbgsym_9.53.3~dfsg-7+deb11u7_amd64.deb ee0c6fdd24c67a7b715dd1d8fa5abaa8 94332 text optional ghostscript-x_9.53.3~dfsg-7+deb11u7_amd64.deb 9000df5162c8f9c87052a22b2abfcbcb 11706 text optional ghostscript_9.53.3~dfsg-7+deb11u7_amd64-buildd.buildinfo 5453a9e4e11609f0ab6c4f7e5e90f45a 98468 text optional ghostscript_9.53.3~dfsg-7+deb11u7_amd64.deb 23c0a0883516bc67291506315c13e596 80444 libdevel optional libgs-dev_9.53.3~dfsg-7+deb11u7_amd64.deb d271fcb2dd41dd899993373b26ee70b1 7936228 debug optional libgs9-dbgsym_9.53.3~dfsg-7+deb11u7_amd64.deb a5d308662916cce9cbd918f8b441ced4 2244380 libs optional libgs9_9.53.3~dfsg-7+deb11u7_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEErEDrIdpJkzFMm6K+PyQET5WCY90FAmY+YD0ACgkQPyQET5WC Y93S8w/+IomHgDkq+OXKZVRTh3bIhoJ0rFknDUwqYQWJkM9Gi1tEWUGviOO2AoeD fbF0H1+TMZKXDf0j323pMM54bEAyokH8/1HbMbVuO5f+gIstsHrzkScd3J3kcsYQ HGMEXPHtxzGHR4ufUU1G1IO206MD3xnoQ/rSpSK22jjTV7zVYZlrTn6zpz8Frlz1 B1fuDCVi9yyXlOhoDvbZwagcdRb5Gaf4L1HAyVN4zZ/ZqxGJI8v9QwpvmmRN9eux D4qsQA8gPhBHNybk+WKPa6iJceivrE315LdKIx4nxANLtjpEVrO93pMU7pWjsBFQ n3eRWXv89impSur/qmYbglnoZgeLlHrVt85f5GRNmkhTKz2WEp0iw0LzjBmTke9F 11aoZ03ndD1paPJfUjLfXLLBW38am2TAkZaefRwVE9mFS6hyvWIKJtsYfcwCgDTc 1DMqdSJ2l47bC5oag6Ufri3kBhtRJyYX5ME/is4CaxW+CxMULM94FEZ3AlmUguqs tiZAI+4eOudO1DZowlcPV2reCvJ3/OQs5jkl7bdVrxY9DwpJHOdpb94cH6Q90hKd LjwRDTa5n3+kGBZ9uVnkA8PP6SaXVOb/zltHNd0ULIXvkZYRN3BGuiBCsx2rqudP PkIrKQlCVxnoo5Irb+AE5lNLDhjH4o/4WycGAkmGxAlp4GOImSw= =iuSA -----END PGP SIGNATURE-----