Solution
Please Install the Updated Packages.
Insight
A vulnerability has been found and corrected in ghostscript:
Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter (CVE-2010-1628).
As a precaution ghostscriptc has been rebuilt to link against the system libpng library which was fixed with MDVSA-2010:133
The updated packages have been patched to correct this issue.
Affected
ghostscript on Mandriva Linux 2010.1,
Mandriva Linux 2010.1/X86_64
Severity
Classification
-
CVE CVE-2010-1628 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities