Debian — Security Information — DSA-4336-1 ghostscript
Several vulnerabilities were discovered in Ghostscript, the GPL
PostScript/PDF interpreter, which may result in denial of service,
disclosure of existence and size of arbitrary files, or the execution of
arbitrary code if a malformed Postscript file is processed (despite the
dSAFER sandbox being enabled).
This update rebases ghostscript for stretch to the upstream version 9.25
which includes additional non-security related changes.
For the stable distribution (stretch), these problems have been fixed in
We recommend that you upgrade your ghostscript packages.
For the detailed security status of ghostscript please refer to its
security tracker page at: