Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 72822 - app-text/ghostscript-afpl : segv reading files
Summary: app-text/ghostscript-afpl : segv reading files
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Auditing (show other bugs)
Hardware: x86 Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-11-29 08:29 UTC by Peter Volkov (RETIRED)
Modified: 2005-03-14 12:02 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Peter Volkov (RETIRED) gentoo-dev 2004-11-29 08:29:57 UTC
Hello.
Look. There is a bug in ghostscript:
http://bugs.ghostscript.com/show_bug.cgi?id=687818

I've moved to 8.15 and everything works much better. I think it's good time to make it stable.

Reproducible: Always
Steps to Reproduce:
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2004-11-30 03:30:07 UTC
If real, this *could* be exploited by using a malicious PDF file.

printing herd / x86 team : please test and mark 8.15 stable, as it seems to be stable anyway.
Comment 2 Heinrich Wendel (RETIRED) gentoo-dev 2004-11-30 05:57:26 UTC
stable on x86
Comment 3 Luke Macken (RETIRED) gentoo-dev 2004-11-30 11:41:08 UTC
Security, please vote on GLSA.
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2004-11-30 12:07:14 UTC
Without more information, we won't issue a GLSA. Someone with time should reproduce and look at the diff to see what was fixed and if it's exploitable.
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-11-30 23:30:33 UTC
Seems like a job for auditing.
Comment 6 Matthias Geerdsen (RETIRED) gentoo-dev 2004-12-01 03:14:03 UTC
Yep, agreeing with comments #4, #5
Comment 7 Thierry Carrez (RETIRED) gentoo-dev 2004-12-01 09:08:26 UTC
There are a lot of SEGV fixes in gs.
We'll suppose these are not exploitable, unless proves otherwise.
Switching to auditing as this package may be a nice target.
Comment 8 rob holland (RETIRED) gentoo-dev 2005-03-10 12:20:43 UTC
fwiw the bug referenced below is a segfault due to a huge stack, can't see it being exploitable (not that I'm an expert).
Comment 9 rob holland (RETIRED) gentoo-dev 2005-03-10 12:21:07 UTC
s/below/above/ ;)
Comment 10 Heinrich Wendel (RETIRED) gentoo-dev 2005-03-14 11:06:41 UTC
so...
Comment 11 Thierry Carrez (RETIRED) gentoo-dev 2005-03-14 12:02:38 UTC
so it's CLOSED as a fixed non-security issue.