Has anyone heard of this new RCE bug exploit in Ghostscript Library?  [Solved]

For interesting topics. But remember this is a Linux Forum. Do not post offensive topics that are meant to cause trouble with other members or are derogatory towards people of different genders, race, color, minors (this includes nudity and sex), politics or religion. Let's try to keep peace among the community and for visitors.

No spam on this or any other forums please! If you post advertisements on these forums, your account may be deleted.

Do not copy and paste entire or even up to half of someone else's words or articles into posts. Post only a few sentences or a paragraph and make sure to include a link back to original words or article. Otherwise it's copyright infringement.

You can talk about other distros here, but no MX bashing. You can email the developers of MX if you just want to say you dislike or hate MX.
Message
Author
User avatar
CyberGhost
Posts: 210
Joined: Thu Jan 10, 2019 9:27 pm

Has anyone heard of this new RCE bug exploit in Ghostscript Library?

#1 Post by CyberGhost »

Hi, hope all of you are well. From what I read many different kinds of softwares use Ghostscript including Libre Office. There are a few more listed in the article. It also says to upgrade to the newest version of Ghostscript which is v10.03.1, and I checked the Enabled Repos of MXPI and there is only version 10.0.0 at this time. I checked the MX Test repos and Debian Backports too and the same version is there as well. Maybe no one has caught this yet or maybe they haven't issued a patch for it yet perhaps? Let me know your thoughts and if this is even something to be concerned about. Thanks! Article link below:

https://www.bleepingcomputer.com/news/s ... n-attacks/

User avatar
anticapitalista
Developer
Posts: 4288
Joined: Sat Jul 15, 2006 10:40 am

Re: Has anyone heard of this new RCE bug exploit in Ghostscript Library?  [Solved]

#2 Post by anticapitalista »

Seems like Debian applied the patch in May

Uniprint device - prevent string configuration changes when SAFER
(CVE-2024-29510)

https://metadata.ftp-master.debian.org/ ... _changelog
anticapitalista
Reg. linux user #395339.

Philosophers have interpreted the world in many ways; the point is to change it.

antiX with runit - lean and mean.
https://antixlinux.com

User avatar
thinkpadx
Posts: 670
Joined: Thu Aug 13, 2020 8:34 pm

Re: Has anyone heard of this new RCE bug exploit in Ghostscript Library?

#3 Post by thinkpadx »

Thanks for the info anticapitalista!

User avatar
CyberGhost
Posts: 210
Joined: Thu Jan 10, 2019 9:27 pm

Re: Has anyone heard of this new RCE bug exploit in Ghostscript Library?

#4 Post by CyberGhost »

@anticapitalista Thanks so much for the info and your input! Good to know!

Post Reply

Return to “General”