Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Sun, 21 Oct 2018 02:04:50 +0100
From: Ken Moffat <zarniwhoop@...world.com>
To: oss-security@...ts.openwall.com
Subject: Re: Attempting to patch ghostscript-9.25

On Sat, Oct 20, 2018 at 11:42:20AM +0000, Jordan Glover wrote:
> ‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐
> On Saturday, October 20, 2018 3:47 AM, Ken Moffat <zarniwhoop@...world.com> wrote:
> 
> >
> > The patch is a bit big, so I've uploaded it to
> > http://www.linuxfromscratch.org/~ken/provisional/ as
> > ghostscript-9.25-security_fixes-2.patch
> >
> > 'provisional' until I find out if it protects adequately. If there
> > turn out ot be problems, I suppose I'll need to renumber later
> > versions.
> >
I've now been given an exploit, in a PDF (I was not subscribed here
until Friday, missed some of the earleir stuff).  That -2 patch fixes
it.

Tested with evince (which now loops trying to rended an empty page,
same as with the .ps exploit), so I've committed it in BLFS.  Will
take down the 'provisional' copy in a few days.

> I think the easiest way is to build on upstream git snapshot.
> All of its contents will be included in future release anyway.
> 
> Jordan

If upstream are like anywhere else, some changes get backed out or
modified so they might not be there when 9.26 is released.  OTOH,
one of the changes I ignored might stop evince looping on a
'damaged' PDF.  Swings and roundabouts.

ĸen
-- 
                        Is it about a bicycle ?

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.