oss-sec mailing list archives
Re: Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284
From: Jordan Glover <Golden_Miller83 () protonmail ch>
Date: Thu, 18 Oct 2018 13:25:29 +0000
‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐ On Thursday, October 18, 2018 2:32 PM, Tavis Ormandy <taviso () google com> wrote:
On Thu, Oct 18, 2018 at 3:51 AM Jordan Glover <Golden_Miller83 () protonmail ch> wrote:Do you know if upstream is going to make new release soon or distros should take the pain and backport all of those themselves?AFAIK upstream only makes quarterly releases, so I think you need to backport. Tavis.
In normal, boring times yes but 9.25 was available just 10 days after 9.24 as urgent security release and it seems it was still not enough. Jordan
Current thread:
- ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284 Tavis Ormandy (Oct 16)
- Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284 Perry E. Metzger (Oct 16)
- Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284 Tavis Ormandy (Oct 16)
- Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284 Rich Felker (Oct 16)
- Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284 Bob Friesenhahn (Oct 17)
- Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284 Tavis Ormandy (Oct 16)
- Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284 Hanno Böck (Oct 16)
- Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284 Perry E. Metzger (Oct 16)
- Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284 Perry E. Metzger (Oct 16)
- Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284 Tavis Ormandy (Oct 17)
- Re: Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284 Jordan Glover (Oct 18)
- Re: Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284 Tavis Ormandy (Oct 18)
- Re: Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284 Jordan Glover (Oct 18)
- Re: Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284 Jordan Glover (Oct 18)