Processed: Re: Bug#839260: ghostscript: various sandbox bypasses

2016-10-05 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > clone 839260 -1 Bug #839260 [ghostscript] ghostscript: various sandbox bypasses Bug 839260 cloned as bug 839841 > retitle -1 ghostscript: .libfile doesn't check PermitFileReading array, > allowing remote file disclosure Bug #839841 [ghostscript]

Bug#839260: ghostscript: various sandbox bypasses

2016-10-05 Thread Salvatore Bonaccorso
clone 839260 -1 retitle -1 ghostscript: .libfile doesn't check PermitFileReading array, allowing remote file disclosure forwarded -1 http://bugs.ghostscript.com/show_bug.cgi?id=697169 retitle 839260 ghostscript: various userparams allow %pipe% in paths, allowing remote shell command execution for

Bug#839260: ghostscript: various sandbox bypasses

2016-09-30 Thread Florian Weimer
Package: ghostscript Version: 9.19~dfsg-3 Tags: security Severity: grave Tavis Ormandy has reported several sandbox bypasses on the oss-security mailing list. (also see follow-ups) Filed upstream as: