Bug#584064: texlive-base-bin: Security bugs in ghostscript

2010-05-31 Thread paul . szabo
Dear Norbert, > That is right, but still it is a bug of ghostscript and should > be treated there, not anywhere else. Yes. And when they advise you to use -P- (and refuse to make that the default), you just need to follow: you need to change. (But yes, such a gs requirement, leaving it "insecure

Bug#584064: texlive-base-bin: Security bugs in ghostscript

2010-05-31 Thread Norbert Preining
On Di, 01 Jun 2010, paul.sz...@sydney.edu.au wrote: > The bug affects all users of ghostscript. They know that to be That is right, but still it is a bug of ghostscript and should be treated there, not anywhere else. Furthermore, gs is not run with extended priviliges, so that does not compromise

Bug#584064: texlive-base-bin: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
Package: texlive-base-bin Version: 2007.dfsg.2-4+lenny2 Severity: grave Tags: security Justification: user security hole Please note remote execute-any-code security bugs in ghostscript: http://bugs.debian.org/583183 This package suggests ghostscript, and may be affected. Please evaluate the