Hi folks, It is my unhappy lot to report that, after many years of a clean security record,[1] it looks like we're going to have to roll a security update.
Please expect a groff 1.24.2 release in the coming days. I plan no release candidates and minimal code changes. Distributors, you may find it necessary to backport the changes in 1.24.2 to older versions of groff in your maintenance/stable releases. All of the problems are of long standing. None of the problems is exploitable by rendering a man page to the terminal, to PostScript, or to PDF. I will not include regression tests for the problems in 1.24.2, but I _do_ expect to ship them in the groff 1.25.0.rc3 release candidate that I plan to make some time afterward. As yet I have no firm schedule for either event. I will hold back pushing these regression tests to groff's "master" branch in its public Git repository until I am ready to tag 1.25.0.rc3. I acknowledge that by disclosing even this much, I may be giving hints to the mad dogs of LLM-assisted vulnerability scanning and exploitation. I further observe that the model of anointing an elite tier of industry professionals who receive advance warning of issues, and with whom "embargoes" of information are arranged, is cracking under the strain of the evolving security landscape. The famed "vendor-sec" list broke in half and sank as long ago as groff's most recent security updates. The groff project lacks the staff to maintain more than one stable release. But I am happy to consult with security engineers to advise on any issues you encounter if backporting the forthcoming fixes is not straightforward. Beyond that, if you have expectations of a Service Level Agreement from groff developers, you are at liberty to negotiate for compensated labor. Fellow groff developers, I ask for your attention to recently filed "private" tickets in Savannah. If you are a member of the "groff" group and logged in, you should be able to access the tickets straightforwardly. https://savannah.gnu.org/bugs/index.php (If you're a member of more than one Savannah group, I expect you'll have to select the "groff" one. I don't know for sure, because I am not.) It is my intention to set the tickets' visibility to "Public" once they are fixed, and their regression tests published, on the "master" branch. Lamentably yours, Branden [1] ...about 14 years, if my Web searches haven't failed me. (CVE-2009-5081 and CVE-2009-5044 were not published until June 2011, and distributor updates appear to be dated 2012; I cannot make sense of the timeline.)
signature.asc
Description: PGP signature
