Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 28 Oct 2009 12:58:56 +0000 (GMT)
From: Mark J Cox <mjc@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re:  Re: ghostscript CVE for multiple NULL dereferences
 in JBIG2 decoder

> The same PoC crashes xpdf. I'm not aware of any CVE id being assigned for
> this issue other than the one for Adobe Reader.

So I've deliberately not allocated one because we generally do not 
consider a crash of a user application like a PDF reader to be a security 
issue.  However CVE does have a few cases where CVE names were allocated 
for such cases, so if any vendor here is going to treat this as a security 
issue let me know and I'll allocate a name for tracking purposes.

Thanks, Mark

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.