"G. Branden Robinson" <[email protected]> writes:

> It is my unhappy lot to report that, after many years of a clean
> security record,[1] it looks like we're going to have to roll a security
> update.
>
> Please expect a groff 1.24.2 release in the coming days.  I plan no
> release candidates and minimal code changes.
>
> Distributors, you may find it necessary to backport the changes in
> 1.24.2 to older versions of groff in your maintenance/stable releases.
> All of the problems are of long standing.
>
> None of the problems is exploitable by rendering a man page to the
> terminal, to PostScript, or to PDF.

FWIW, for GNU Inetutils, which I stumbled upon the misfortune of
managing security issues for, I disclose security issues privately to
the distros or linux-distros list [1]. Afterwards, typically around a
week later, I post them publicly on oss-security, as is required by that
page. It seems to get things patched up pretty quickly, so I figured I
would share that with you.

I'm hoping that you didn't hype us up with this public message for a
markdown-formatted document arguing that a fuzzed input can cause a NULL
pointer dereference, and that it should be treated as a CVSS 10000
remote code execution security vulnerability, right? :)

Collin

[1] https://oss-security.openwall.org/wiki/mailing-lists/distros

Reply via email to