Bug#592569: Bug#584653: Patch to close CVE-2010-2055

2010-11-21 Thread paul . szabo
Dear Jonas, Quoting out of order. > ... it is also possible to tell a user to execute "rm -rf ~/" That would be an argument, if the issue was that the bad guy had to convince you to do "gs -dNOSAFER x.ps". But no, he only has to "trick" you into using gs as "god intended". > ... I choose to not

Bug#592569: Bug#584653: Patch to close CVE-2010-2055

2010-11-20 Thread Jonas Smedegaard
On Sun, Nov 21, 2010 at 06:04:13PM +1100, paul.sz...@sydney.edu.au wrote: Dear Jonas, deb http://debian.jones.dk/ squeeze printing I have now upgraded a machine to squeeze and tried your ghostscript 9.00~dfsg-1~0jones1 package, it works perfectly, thanks. [snip] Could your package include the

Bug#592569: Bug#584653: Patch to close CVE-2010-2055

2010-11-20 Thread paul . szabo
Dear Jonas, >>> deb http://debian.jones.dk/ squeeze printing >> >>I have now upgraded a machine to squeeze and tried your >>ghostscript 9.00~dfsg-1~0jones1 >>package, it works perfectly, thanks. >>[snip] >>Could your package include the patch for bug #592569 also, >>to have -dSAFER as default? > >

Bug#592569: Bug#584653: Patch to close CVE-2010-2055

2010-11-20 Thread Jonas Smedegaard
Hi Paul, On Sun, Nov 21, 2010, paul.sz...@sydney.edu.au wrote (at bug#584653): ... I have backported it ... deb http://debian.jones.dk/ squeeze printing I have now upgraded a machine to squeeze and tried your ghostscript 9.00~dfsg-1~0jones1 package, it works perfectly, thanks. [snip] Could y