Bug#592569: ghostscript: Please make -dSAFER the default

2011-01-14 Thread Jonathan Nieder
retitle 592569 gs: ps documents can overwrite arbitrary files unless -dSAFER is used quit Hi Paul, Paul Szabo wrote: > Please make the -dSAFER option the default. > > For discussion, rationale etc please see bugs #583183 and #584663 Thanks for a reminder. I'm retitling this bug to clarify th

Bug#592569: ghostscript: Please make -dSAFER the default

2010-08-19 Thread paul . szabo
I am getting distressed: - having now seen DSA2093, which did not fix these issues - looking in http://security-tracker.debian.org/tracker/CVE-2010-2055 + which does not list bug numbers, but says: [lenny] - ghostscript (too risky for regressions) (does that mean no lenny fix is

Bug#592569: ghostscript: Please make -dSAFER the default

2010-08-13 Thread Jonas Smedegaard
On Fri, Aug 13, 2010 at 09:10:20AM +1000, Paul Szabo wrote: Dear Jonas, ... highest severities are treated as "RC" ... Which severities are those: grave and critical? ... http://www.debian.org/Bugs/Developer#severities ... Your question seems rethoric: Answer is explicitly written at above UR

Bug#592569: ghostscript: Please make -dSAFER the default

2010-08-12 Thread Paul Szabo
Dear Jonas, >>> ... highest severities are treated as "RC" ... >>Which severities are those: grave and critical? >>... http://www.debian.org/Bugs/Developer#severities ... > Your question seems rethoric: Answer is explicitly written at above URL. You are right, my mistake. (Not rhetoric, but "look

Bug#592569: ghostscript: Please make -dSAFER the default

2010-08-12 Thread Jonas Smedegaard
On Thu, Aug 12, 2010 at 10:07:44PM +1000, paul.sz...@sydney.edu.au wrote: ... Severity tags relate to the package globally, and the highest severities are treated as "RC" ... Which severities are those: grave and critical? Quoting from http://www.debian.org/Bugs/Developer#severities : Your q

Bug#592569: ghostscript: Please make -dSAFER the default

2010-08-12 Thread paul . szabo
Dear Jonas, > ... Severity tags relate to the package globally, and the highest > severities are treated as "RC" ... Which severities are those: grave and critical? Quoting from http://www.debian.org/Bugs/Developer#severities : grave ... introduces a security hole allowing access to the a

Bug#592569: ghostscript: Please make -dSAFER the default

2010-08-12 Thread Jonas Smedegaard
On Thu, Aug 12, 2010 at 07:30:57AM +1000, paul.sz...@sydney.edu.au wrote: ... there's no need to have it of RC severity ... Is RC same as grave? (I guess yes.) A common mistake is to tag based on personal use. Severity tags relate to the package globally, and the highest severities are trea

Bug#592569: ghostscript: Please make -dSAFER the default

2010-08-11 Thread paul . szabo
Dear Moritz, > ... there's no need to have it of RC severity ... Is RC same as grave? (I guess yes.) > ... this behaviour of Ghostscript is well known and documented ... Well known to a few elite. Is badly documented, e.g. the Debian man page mentions only in passing that -dSAFER ... [is] str

Bug#592569: ghostscript: Please make -dSAFER the default

2010-08-11 Thread Moritz Muehlenhoff
severity 592569 important thanks On Wed, Aug 11, 2010 at 01:00:49PM +1000, Paul Szabo wrote: > Package: ghostscript > Version: 8.62.dfsg.1-3.2lenny4 > Severity: grave > Tags: security > Justification: user security hole > > > Please make the -dSAFER option the default. > > For discussion, ratio

Bug#592569: ghostscript: Please make -dSAFER the default

2010-08-10 Thread Paul Szabo
Package: ghostscript Version: 8.62.dfsg.1-3.2lenny4 Severity: grave Tags: security Justification: user security hole Please make the -dSAFER option the default. For discussion, rationale etc please see bugs #583183 and #584663, and particularly: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=5