oss-sec mailing list archives

Re: Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284


From: Tavis Ormandy <taviso () google com>
Date: Thu, 18 Oct 2018 05:32:18 -0700

On Thu, Oct 18, 2018 at 3:51 AM Jordan Glover <Golden_Miller83 () protonmail ch>
wrote:

Do you know if upstream is going to make new release soon or distros
should take the
pain and backport all of those themselves?


AFAIK upstream only makes quarterly releases, so I think you need to
backport.

Tavis.

Current thread: