Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20181009153006.GF21509@takahe.colorado.edu>
Date: Tue, 9 Oct 2018 09:30:06 -0600
From: Leonid Isaev <leonid.isaev@...a.colorado.edu>
To: oss-security@...ts.openwall.com
Subject: Re: ghostscript: bypassing executeonly to escape
 -dSAFER sandbox (CVE-2018-17961)

On Tue, Oct 09, 2018 at 06:58:39AM -0700, Tavis Ormandy wrote:
> Full working exploit that works in the last few versions is attached,
> viewing it in evince, imagemagick, gimp, okular, etc should add a line to
> ~/.bashrc.

Add zathura to the above list :)

> p.s. plz can we deprecate untrusted postscript :(

Which means any postscript file downloaded from the internet... Then how should
people read arXiv.org, for example?

Thanks,
L.

-- 
Leonid Isaev

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.