oss-sec mailing list archives

Re: Re: ghostscript CVE for multiple NULL dereferences in JBIG2 decoder


From: Mark J Cox <mjc () redhat com>
Date: Wed, 28 Oct 2009 12:58:56 +0000 (GMT)

The same PoC crashes xpdf. I'm not aware of any CVE id being assigned for
this issue other than the one for Adobe Reader.

So I've deliberately not allocated one because we generally do not consider a crash of a user application like a PDF reader to be a security issue. However CVE does have a few cases where CVE names were allocated for such cases, so if any vendor here is going to treat this as a security issue let me know and I'll allocate a name for tracking purposes.

Thanks, Mark


Current thread: