ELA-540-1 ghostscript security update

heap-based buffer overflow

2022-01-16
Packageghostscript
Version9.26a~dfsg-0+deb8u8
Related CVEs CVE-2021-45944 CVE-2021-45949


Multiple security issues were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which could result in denial of service and potentially the execution of arbitrary code if malformed document files are processed.



For Debian 8 jessie, these problems have been fixed in version 9.26a~dfsg-0+deb8u8.

We recommend that you upgrade your ghostscript packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.