Bug#856142: ghostscript: CVE-2017-6196

2017-02-27 Thread Salvatore Bonaccorso
Control: notfound -1 9.06~dfsg-2 Control: notfound -1 9.20~dfsg-2 Hi After some more investigation I suspect the issue actually was only introduced with http://git.ghostscript.com/?p=ghostpdl.git;h=cffb5712bc10c2c2f46adf311fc74aaae74cb784 and indeed applying that commit on top of the sid packagi

Bug#856142: ghostscript: CVE-2017-6196

2017-02-26 Thread Salvatore Bonaccorso
Control: tags -1 + patch Attached proposed debdiff (not yet uploaded, neither to a delayed queue). Regards, Salvatore diff -Nru ghostscript-9.20~dfsg/debian/changelog ghostscript-9.20~dfsg/debian/changelog --- ghostscript-9.20~dfsg/debian/changelog 2017-01-25 05:26:10.0 +0100 +++ g

Bug#856142: ghostscript: CVE-2017-6196

2017-02-25 Thread Thorsten Alteholz
Package: ghostscript Severity: important Tags: security Hi, the following vulnerability was published for ghostscript. CVE-2017-6196[0]: | Multiple use-after-free vulnerabilities in the gx_image_enum_begin | function in base/gxipixel.c in Ghostscript before | ecceafe3abba2714ef9b432035fe0739d9b