Your message dated Tue, 1 Jun 2010 16:29:13 +0300
with message-id <[email protected]>
and subject line Re: [Pkg-cups-devel] Bug#584003: cups-pdf: Security bugs in
ghostscript
has caused the Debian Bug report #584003,
regarding cups-pdf: Security bugs in ghostscript
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
584003: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584003
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: cups-pdf
Severity: grave
Tags: security
Justification: user security hole
Please note remote execute-any-code security bugs in ghostscript:
http://bugs.debian.org/583183
This package depends on ghostscript, and may be affected. Please
evaluate the security of this package, and fix if needed.
Thanks,
Paul Szabo [email protected] http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics University of Sydney Australia
-- System Information:
Debian Release: 5.0.4
APT prefers stable
APT policy: (500, 'stable')
Architecture: i386 (i686)
Kernel: Linux 2.6.26-pk03.17-svr (SMP w/8 CPU cores)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/bash
--- End Message ---
--- Begin Message ---
On Tue, Jun 1, 2010 at 4:06 AM, Paul Szabo <[email protected]> wrote:
> Package: cups-pdf
> Severity: grave
> Tags: security
> Justification: user security hole
>
>
> Please note remote execute-any-code security bugs in ghostscript:
>
> http://bugs.debian.org/583183
>
> This package depends on ghostscript, and may be affected. Please
> evaluate the security of this package, and fix if needed.
In the future, please have the decency to consult with debian-devel
before mass-filing bugs. Also check whether the issue actually
applies to a package before filing a bug against it. We already call
-dSAFER and drop privileges early, so we're already protected as it
is. Closing.
Martin-Éric
--- End Message ---