"G. Branden Robinson" <[email protected]> writes:
> It is my unhappy lot to report that, after many years of a clean > security record,[1] it looks like we're going to have to roll a security > update. > > Please expect a groff 1.24.2 release in the coming days. I plan no > release candidates and minimal code changes. > > Distributors, you may find it necessary to backport the changes in > 1.24.2 to older versions of groff in your maintenance/stable releases. > All of the problems are of long standing. > > None of the problems is exploitable by rendering a man page to the > terminal, to PostScript, or to PDF. FWIW, for GNU Inetutils, which I stumbled upon the misfortune of managing security issues for, I disclose security issues privately to the distros or linux-distros list [1]. Afterwards, typically around a week later, I post them publicly on oss-security, as is required by that page. It seems to get things patched up pretty quickly, so I figured I would share that with you. I'm hoping that you didn't hype us up with this public message for a markdown-formatted document arguing that a fuzzed input can cause a NULL pointer dereference, and that it should be treated as a CVSS 10000 remote code execution security vulnerability, right? :) Collin [1] https://oss-security.openwall.org/wiki/mailing-lists/distros
