For release note, see: https://ghostscript.readthedocs.io/en/gs10.06.0/News.html This fixes the following vulnerabilities: - CVE-2025-59798: Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c. https://www.cve.org/CVERecord?id=CVE-2025-59798 - CVE-2025-59799: Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value. https://www.cve.org/CVERecord?id=CVE-2025-59799 - CVE-2025-59800: In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap- based buffer overflow in ocr_line8. https://www.cve.org/CVERecord?id=CVE-2025-59800 - CVE-2025-59801: In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked. https://www.cve.org/CVERecord?id=CVE-2025-59801 Also remove patch that is now applied upstream, and add new patch from upstream to fix a compilation issue on 32bits platforms Signed-off-by: Titouan Christophe <titouan.christophe@mind.be> [Julien: - add link to release note in commit log - fix URL in hash file comment ] Signed-off-by: Julien Olivain <ju.o@free.fr>
64 lines
2.5 KiB
Diff
64 lines
2.5 KiB
Diff
From 3c0be6e4fcffa63e4a5a1b0aec057cebc4d2562f Mon Sep 17 00:00:00 2001
|
|
From: Ken Sharp <Ken.Sharp@artifex.com>
|
|
Date: Wed, 10 Sep 2025 08:55:30 +0100
|
|
Subject: [PATCH] Fix 32-bit build
|
|
|
|
Bug #708824 "ghostscript 10.06.0 compilation failure on 32-bit archs"
|
|
|
|
nbytes shiouldn't be an intptr_t, it doesn't get used for pointer
|
|
arithmetic. Previously it was a uint, should be a int64_t, to fit with
|
|
all the other devices.
|
|
|
|
Checked other warnings, and found a (very minor) one in gdevdbit.c, fix
|
|
that while we're here (signed/unsigned mismatch, we don't really care).
|
|
|
|
Upstream: https://github.com/ArtifexSoftware/ghostpdl/commit/3c0be6e4fcffa63e4a5a1b0aec057cebc4d2562f
|
|
|
|
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
|
|
---
|
|
base/gdevdbit.c | 2 +-
|
|
base/gdevmpla.c | 6 +++---
|
|
2 files changed, 4 insertions(+), 4 deletions(-)
|
|
|
|
diff --git a/base/gdevdbit.c b/base/gdevdbit.c
|
|
index e07cc3f3b8..1b5c69325b 100644
|
|
--- a/base/gdevdbit.c
|
|
+++ b/base/gdevdbit.c
|
|
@@ -191,7 +191,7 @@ gx_default_copy_alpha_hl_color(gx_device * dev, const byte * data, int data_x,
|
|
fit_copy(dev, data, data_x, raster, id, x, y, width, height);
|
|
row_alpha = data;
|
|
out_raster = bitmap_raster(width * (size_t)byte_depth);
|
|
- if (check_64bit_multiply(out_raster, ncomps, &product) != 0)
|
|
+ if (check_64bit_multiply(out_raster, ncomps, (int64_t *) &product) != 0)
|
|
return gs_note_error(gs_error_undefinedresult);
|
|
gb_buff = gs_alloc_bytes(mem, product, "copy_alpha_hl_color(gb_buff)");
|
|
if (gb_buff == 0) {
|
|
diff --git a/base/gdevmpla.c b/base/gdevmpla.c
|
|
index 2f0d522561..ffc5ff42e6 100644
|
|
--- a/base/gdevmpla.c
|
|
+++ b/base/gdevmpla.c
|
|
@@ -1954,12 +1954,12 @@ mem_planar_strip_copy_rop2(gx_device * dev,
|
|
int i;
|
|
int j;
|
|
intptr_t chunky_sraster;
|
|
- intptr_t nbytes;
|
|
+ int64_t nbytes;
|
|
byte **line_ptrs;
|
|
byte *sbuf, *buf;
|
|
|
|
chunky_sraster = sraster * (intptr_t)mdev->num_planar_planes;
|
|
- if (check_64bit_multiply(height, chunky_sraster, (size_t *)&nbytes) != 0)
|
|
+ if (check_64bit_multiply(height, chunky_sraster, &nbytes) != 0)
|
|
return gs_note_error(gs_error_undefinedresult);
|
|
buf = gs_alloc_bytes(mdev->memory, nbytes, "mem_planar_strip_copy_rop(buf)");
|
|
if (buf == NULL) {
|
|
@@ -2003,7 +2003,7 @@ mem_planar_strip_copy_rop2(gx_device * dev,
|
|
intptr_t i;
|
|
intptr_t chunky_t_raster;
|
|
int chunky_t_height;
|
|
- intptr_t nbytes;
|
|
+ int64_t nbytes;
|
|
byte **line_ptrs;
|
|
byte *tbuf, *buf;
|
|
gx_strip_bitmap newtex;
|