oss-sec mailing list archives
Re: CVE request: mat doesn't remove metadata in embedded images in PDFs
From: Holger Levsen <holger () layer-acht org>
Date: Thu, 2 Jun 2016 18:02:40 +0000
On Thu, Jun 02, 2016 at 12:21:34PM -0400, cve-assign () mitre org wrote:
We think you mean that a CVE ID can exist with the rationale of: - as of version 0.7, there will be a required security update in which the embedded-in-a-PDF security problem is resolved - the CVE ID is needed to tag that required security update - as of version 0.7, the https://mat.boum.org/ text may be changed from "images embedded inside PDF may not be cleaned" to something like "images embedded inside complex documents may not be cleaned, but users can rely on cleaning in the specific case of PDF documents" Does that match your intention for the CVE ID?
yes. Though I disagree with the 3rd paragraph a bit, I don't think it's that hard to recursivly process files, eg both https://tracker.debian.org/pkg/strip-nondeterminism (in perl) and https://tracker.debian.org/pkg/diffoscope (in python) do that. -- cheers, Holger
Attachment:
signature.asc
Description: Digital signature
Current thread:
- CVE request: mat doesn't remove metadata in embedded images in PDFs Holger Levsen (Jun 02)
- Re: CVE request: mat doesn't remove metadata in embedded images in PDFs cve-assign (Jun 02)
- Re: CVE request: mat doesn't remove metadata in embedded images in PDFs Holger Levsen (Jun 02)
- Re: CVE request: mat doesn't remove metadata in embedded images in PDFs cve-assign (Jun 02)