Bug#839260: ghostscript: various sandbox bypasses

2016-10-05 Thread Salvatore Bonaccorso
clone 839260 -1 retitle -1 ghostscript: .libfile doesn't check PermitFileReading array, allowing remote file disclosure forwarded -1 http://bugs.ghostscript.com/show_bug.cgi?id=697169 retitle 839260 ghostscript: various userparams allow %pipe% in paths, allowing remote shell command execution for

Bug#839260: ghostscript: various sandbox bypasses

2016-09-30 Thread Florian Weimer
Package: ghostscript Version: 9.19~dfsg-3 Tags: security Severity: grave Tavis Ormandy has reported several sandbox bypasses on the oss-security mailing list. (also see follow-ups) Filed upstream as: