Bug#861295: ghostscript: CVE-2017-8291: shell injection

2017-04-27 Thread Salvatore Bonaccorso
Hi Upstream commits are now available: https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=04b37bbce174eed24edec7ad5b920eb93db4d47d https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=4f83478c88c2e05d6e8d79ca4557eb039354d2f3 Regards, Salvatore

Bug#861295: ghostscript: CVE-2017-8291: shell injection

2017-04-27 Thread Salvatore Bonaccorso
SuSE has caputred the initial report including a reproducer to verify the issue (and verify the fix upstream once landed there): https://bugzilla.suse.com/show_bug.cgi?id=1036453 Regards, Salvatore

Bug#861295: ghostscript: CVE-2017-8291: shell injection

2017-04-27 Thread Salvatore Bonaccorso
On Thu, Apr 27, 2017 at 07:03:05AM +0200, Salvatore Bonaccorso wrote: > Forwarded: https://bugs.ghostscript.com/show_bug.cgi?id=697808 FTR, the bug has been restricted in meanwhile, but did contain a reproducer to demonstrate the issue. Regards, Salvatore

Bug#861295: ghostscript: CVE-2017-8291: shell injection

2017-04-26 Thread Salvatore Bonaccorso
Source: ghostscript Version: 9.06~dfsg-2 Severity: grave Tags: upstream security Justification: user security hole Forwarded: https://bugs.ghostscript.com/show_bug.cgi?id=697808 Hi, the following vulnerability was published for ghostscript. CVE-2017-8291[0]: | Artifex Ghostscript through 2017-04