Rocky Linux 8 [CIQ] セキュリティ更新:ghostscript/ghostscript-debuginfo/ghostscript-debugsourceなど複数の脆弱性(crlsa-2021_1852)

high Nessus プラグイン ID 358488

概要

Rocky Linuxホストに1つ以上のセキュリティ更新プログラムがありません。

説明

Rocky Linux 8ホストには、CIQ crlsa-2021_1852 アドバイザリに記載された複数の脆弱性の影響を受けるパッケージがインストールされています。

* ghostscript:igc_reloc_struct_ptr()のメモリ解放後使用(use-after-free)の脆弱性により、DoSが引き起こされる可能性があります(CVE-2020-14373)

* ghostscript:contrib/lips4/gdevlprn.c の lprn_is_black() でのバッファオーバーフローにより、DoS が発生する可能性があります(CVE-2020-16287)

* ghostscript:devices/gdevpjet.c の pj_common_print_page() におけるバッファオーバーフローにより、DoS が引き起こされる可能性があります(CVE-2020-16288)

* ghostscript:devices/gdev3852.c の jetp3852_print_page() のバッファオーバーフローにより、DoS が引き起こされる可能性があります(CVE-2020-16290)

* ghostscript:contrib/gdevdj9.c のバッファオーバーフローにより、DoS が引き起こされる可能性があります(CVE-2020-16291)

* ghostscript:contrib/japanese/gdevmjc.c の mj_raster_cmd() でのバッファオーバーフローにより、DoS が引き起こされる可能性があります(CVE-2020-16292)

* ghostscript:base/gxblend.cのcompose_group_nonknockout_nonblend_isolated_allmask_common()でのNULLポインターデリファレンスにより、DoSが発生する可能性があります(CVE-2020-16293)

* ghostscript:devices/gdevepsc.c の epsc_print_page() のバッファオーバーフローにより、DoS が引き起こされる可能性があります(CVE-2020-16294)

* ghostscript:devices/gdevclj.c の clj_media_size() での NULL ポインターデリファレンスにより、DoS が発生する可能性があります(CVE-2020-16295)

* ghostscript:contrib/lips4/gdevlips.c の GetNumWrongData() のバッファオーバーフローにより、DoS が引き起こされる可能性があります(CVE-2020-16296)

* ghostscript:contrib/gdevbjca.c の FloydSteinbergDitheringC() におけるバッファオーバーフローにより、DoS が引き起こされる可能性があります(CVE-2020-16297)

* ghostscript:contrib/japanese/gdevmjc.c の mj_color_correct() でのバッファオーバーフローにより、DoS が発生する可能性があります(CVE-2020-16298)

* ghostscript:contrib/japanese/gdev10v.c の bj10v_print_page() のゼロ除算により、DoS が発生する可能性があります(CVE-2020-16299)

* ghostscript:devices/gdevtfnx.c の tiff12_print_page() のバッファオーバーフローにより、DoS が引き起こされる可能性があります(CVE-2020-16300)

* ghostscript:devices/gdevokii.cのokiibm_print_page1()でのバッファオーバーフローにより、DoSが引き起こされる可能性があります(CVE-2020-16301)

* ghostscript:devices/gdev3852.c の jetp3852_print_page() のバッファオーバーフローにより、権限昇格が引き起こされる可能性があります(CVE-2020-16302)

* ghostscript:devices/vector/gdevxps.c の xps_finish_image_path() の use-after-free により、権限昇格が引き起こされる可能性があります(CVE-2020-16303)

* ghostscript:base/gxicolor.c の image_render_color_thresh() のバッファオーバーフローにより、DoS が引き起こされる可能性があります(CVE-2020-16304)

* ghostscript:devices/gdevtsep.cのNULLポインターデリファレンスによりDoSが発生する可能性があります(CVE-2020-16306)

* ghostscript:devices/vector/gdevtxtw.c および psi/zbfont.c の NULL ポインターデリファレンスにより、DoS が発生する可能性があります(CVE-2020-16307)

* ghostscript:devices/gdevcdj.c の p_print_image() におけるバッファオーバーフローにより、DoS が引き起こされる可能性があります(CVE-2020-16308)

* ghostscript:devices/gdevlxm.c の lxm5700m_print_page() のバッファオーバーフローにより、DoS が発生する可能性があります(CVE-2020-16309)

* ghostscript:devices/gdevdm24.c の dot24_print_page() のゼロ除算により、DoS が発生する可能性があります(CVE-2020-16310)

* ghostscript:contrib/lips4/gdevlips.c の GetNumSameData() でのバッファオーバーフローにより、DoS が引き起こされる可能性があります(CVE-2020-17538)

* ghostscript:devices/gdevcif.c の cif_print_page() におけるバッファオーバーフローにより、DoS が引き起こされる可能性があります(CVE-2020-16289)

* ghostscript:contrib/japanese/gdev10v.c の pcx_write_rle() でのバッファオーバーフローにより、DoS が引き起こされる可能性があります(CVE-2020-16305)

Tenableは、前述の記述ブロックをCIQセキュリティアドバイザリから直接抽出しています。

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

CIQアドバイザリ crlsa-2021_1852のガイダンスに基づいて、影響を受けるパッケージを更新してください。

参考資料

https://access.redhat.com/errata/RHSA-2021:1852

https://bugzilla.redhat.com/show_bug.cgi?id=1870149

https://bugzilla.redhat.com/show_bug.cgi?id=1870152

https://bugzilla.redhat.com/show_bug.cgi?id=1870159

https://bugzilla.redhat.com/show_bug.cgi?id=1870162

https://bugzilla.redhat.com/show_bug.cgi?id=1870165

https://bugzilla.redhat.com/show_bug.cgi?id=1870167

https://bugzilla.redhat.com/show_bug.cgi?id=1870169

https://bugzilla.redhat.com/show_bug.cgi?id=1870171

https://bugzilla.redhat.com/show_bug.cgi?id=1870175

https://bugzilla.redhat.com/show_bug.cgi?id=1870179

https://bugzilla.redhat.com/show_bug.cgi?id=1870227

https://bugzilla.redhat.com/show_bug.cgi?id=1870229

https://bugzilla.redhat.com/show_bug.cgi?id=1870231

https://bugzilla.redhat.com/show_bug.cgi?id=1870237

https://bugzilla.redhat.com/show_bug.cgi?id=1870240

https://bugzilla.redhat.com/show_bug.cgi?id=1870242

https://bugzilla.redhat.com/show_bug.cgi?id=1870244

https://bugzilla.redhat.com/show_bug.cgi?id=1870248

https://bugzilla.redhat.com/show_bug.cgi?id=1870249

https://bugzilla.redhat.com/show_bug.cgi?id=1870256

https://bugzilla.redhat.com/show_bug.cgi?id=1870257

https://bugzilla.redhat.com/show_bug.cgi?id=1870258

https://bugzilla.redhat.com/show_bug.cgi?id=1870262

https://bugzilla.redhat.com/show_bug.cgi?id=1870266

https://bugzilla.redhat.com/show_bug.cgi?id=1870267

https://bugzilla.redhat.com/show_bug.cgi?id=1873239

https://bugzilla.redhat.com/show_bug.cgi?id=1874523

https://bugzilla.redhat.com/show_bug.cgi?id=1899902

https://errata.build.resf.org/RLSA-2021:1852

http://www.nessus.org/u?db9c8240

http://www.nessus.org/u?e0eb8b1a

プラグインの詳細

深刻度: High

ID: 358488

ファイル名: ciq_rocky_linux_8_crlsa-2021_1852.nasl

バージョン: 1.1

タイプ: Local

公開日: 2026/10/1

更新日: 2026/10/1

サポートされているセンサー: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: Medium

スコア: 4.9

パーセンタイル: 57.12

Vendor

Vendor Severity: Unknown

CVSS v2

リスクファクター: Medium

基本値: 6.8

現状値: 5.3

ベクトル: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS スコアのソース: CVE-2020-16303

CVSS v3

リスクファクター: High

基本値: 7.8

現状値: 7

ベクトル: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:P/RL:O/RC:C

脆弱性情報

必要な KB アイテム: Host/OS/extended-third-party, Host/local_checks_enabled, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/cpu

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2021/5/18

脆弱性公開日: 2020/8/13

参照情報

CVE: CVE-2020-14373, CVE-2020-16287, CVE-2020-16288, CVE-2020-16289, CVE-2020-16290, CVE-2020-16291, CVE-2020-16292, CVE-2020-16293, CVE-2020-16294, CVE-2020-16295, CVE-2020-16296, CVE-2020-16297, CVE-2020-16298, CVE-2020-16299, CVE-2020-16300, CVE-2020-16301, CVE-2020-16302, CVE-2020-16303, CVE-2020-16304, CVE-2020-16305, CVE-2020-16306, CVE-2020-16307, CVE-2020-16308, CVE-2020-16309, CVE-2020-16310, CVE-2020-17538