Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20180827194351.76ac39c6@jabberwock.cb.piermont.com>
Date: Mon, 27 Aug 2018 19:43:51 -0400
From: "Perry E. Metzger" <perry@...rmont.com>
To: Tavis Ormandy <taviso@...gle.com>
Cc: oss-security@...ts.openwall.com
Subject: Re: Re: More Ghostscript Issues: Should we disable
 PS coders in policy.xml by default?

On Mon, 27 Aug 2018 16:02:46 -0700 Tavis Ormandy <taviso@...gle.com>
wrote:
> Here is an update, Artifex made a press release
> <https://www.darkreading.com/prnewswire2.asp?rkey=20180824UN89145&filter=3930>
> listing
> some necessary commits, but the list was incomplete.

They also claimed "Artifex Software is pleased to report that the
recently disclosed security vulnerabilities in Ghostscript have been
resolved.", which, even if they were all patched in their git
repository, which they don't seem to all be, would still not really
be true given the lack of an actual release.

> Here is a list of relevant commits I'm aware of so far, some issues
> are still open with working exploits available. It's my
> understanding that no new release is planned until late September,
> and vendors need to either ship a git snapshot when all issues are
> resolved, or apply patches. I have testcases for each problem, but
> I think the bugs will be visible eventually so I'm not posting them
> here.

If someone would put a git repo onto GitHub with all the available
patches applied on a branch, I'm sure a bunch of people would be
grateful.

Perry
-- 
Perry E. Metzger		perry@...rmont.com

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.