Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 19 Jul 2010 11:12:12 +0200
From: Tomas Hoger <thoger@...hat.com>
To: oss-security@...ts.openwall.com
Cc: brlink@...ian.org
Subject: Re: CVE request: ghostscript and gv

On Sun, 30 May 2010 22:08:12 +0200 Bernhard R. Link wrote:

> Gs's -P- not working (at least for gs_init.ps), is definitly a bug
> that needs to be fixed.

This should be fixed in upstream SVN now.

> I personally would also suggest fixing gs to not look in the current
> directory by default (looking for important stuff in the current
> directory is really always a bad idea). I guess the problem is how to
> fix it.

Following commit should change default from -P to -P- :
  http://svn.ghostscript.com/viewvc?view=rev&revision=11494

Is this the approach other vendors are expecting to use?

-- 
Tomas Hoger / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.