On Tue, Jun 1, 2010 at 7:03 AM, Paul Szabo <paul.sz...@sydney.edu.au> wrote:
Package: recoll
Severity: grave
Tags: security
Justification: user security hole

Please note remote execute-any-code security bugs in ghostscript:
 http://bugs.debian.org/583183

This package suggests ghostscript, and may be affected. Please
evaluate the security of this package, and fix if needed.

Hi Paul,

I don't think this bug is correct for recoll. recoll only 'suggests' 
ghostscript and don't use code from ghostscript. Filing bug at 'gs
package seems right. CC'ng upstream to know more view. Also CC'ng security team 
if it is valid to file a bug like this.

Thanks.

--
Cheers,
Kartik Mistry
Debian GNU/Linux Developer
0xD1028C8D | Identica: @kartikm | IRC: kart_
Blogs: {gu: kartikm, en: ftbfs}.wordpress.com

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to