File _patchinfo of Package patchinfo.9880
<patchinfo incident="9880">
<issue tracker="bnc" id="1129186">VUL-0: EMBARGOED: CVE-2019-3838: ghostscript,ghostscript-library: forceput in DefineResource is still accessible</issue>
<issue tracker="cve" id="2019-3838"/>
<category>security</category>
<rating>important</rating>
<packager>jsmeix</packager>
<description>This update for ghostscript fixes the following issue:
Security issue fixed:
- CVE-2019-3838: Fixed a vulnerability which made forceput operator in DefineResource to be still accessible
which could allow access to file system outside of the constraints of -dSAFER (bsc#1129186).
This update was imported from the SUSE:SLE-12:Update update project.</description>
<summary>Security update for ghostscript</summary>
</patchinfo>