[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
Date: Thu, 2 Apr 2009 13:40:00 +0200
From: Robert Buchholz <rbu@...too.org>
To: oss-security@...ts.openwall.com
Cc: Jan Lieskovsky <jlieskov@...hat.com>,
"Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE request -- ghostscript
On Wednesday 01 April 2009, Jan Lieskovsky wrote:
> Hello Steve,
>
> could you please allocate new CVE ids for the following two
> Ghostscript issues:
>
> 1, DoS (crash) in CCITTFax decoding filter
> References:
> https://bugzilla.redhat.com/show_bug.cgi?id=493442
> https://bugzilla.redhat.com/show_bug.cgi?id=229174
> -^ original report, so CVE-2007-XXXX will be needed
> https://bugzilla.redhat.com/show_bug.cgi?id=493442#c1 (PoC)
The Tim Waugh patch has been incorporated here:
http://svn.ghostscript.com/viewvc?view=rev&revision=8896
Robert
[ CONTENT OF TYPE application/pgp-signature SKIPPED ]
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Hosted by DataForce ISP -
Powered by Openwall GNU/*/Linux