6f984089c0
For release note, see: https://ghostscript.readthedocs.io/en/gs10.06.0/News.html This fixes the following vulnerabilities: - CVE-2025-59798: Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c. https://www.cve.org/CVERecord?id=CVE-2025-59798 - CVE-2025-59799: Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value. https://www.cve.org/CVERecord?id=CVE-2025-59799 - CVE-2025-59800: In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap- based buffer overflow in ocr_line8. https://www.cve.org/CVERecord?id=CVE-2025-59800 - CVE-2025-59801: In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked. https://www.cve.org/CVERecord?id=CVE-2025-59801 Also remove patch that is now applied upstream, and add new patch from upstream to fix a compilation issue on 32bits platforms Signed-off-by: Titouan Christophe <titouan.christophe@mind.be> [Julien: - add link to release note in commit log - fix URL in hash file comment ] Signed-off-by: Julien Olivain <ju.o@free.fr>
6 lines
371 B
Plaintext
6 lines
371 B
Plaintext
# From https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/download/gs10060/SHA512SUMS
|
|
sha512 e9efa6a334cf34703f565f5043dd794452270415b34c2bea260e9dac6c72ebbcbedfa2e4cb9029841f8f582bbce91be8160e135a190081f3262bcf04417f80f1 ghostscript-10.06.0.tar.xz
|
|
|
|
# Hash for license file:
|
|
sha256 8ce064f423b7c24a011b6ebf9431b8bf9861a5255e47c84bfb23fc526d030a8b LICENSE
|