Bug#839118: ghostscript: CVE-2013-5653: getenv and filenameforall ignore -dSAFER

2016-10-12 Thread Salvatore Bonaccorso
Control: severity -1 serious Rationale for severity increase: We ship DSA-3691-1 in jessie containing the fix, and not having the security fix in stretch then would be a regression. Regards, Salvatore

Bug#839118: ghostscript: CVE-2013-5653: getenv and filenameforall ignore -dSAFER

2016-09-28 Thread Florian Weimer
Package: ghostscript Version: 9.06~dfsg-2+deb8u1 Tags: security This issue is now public, but was apparently never properly announced: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=ab109aaeb3ddba59518b036fb288402a65cf7ce8 http://bugs.ghostscript.com/show_bug.cgi?id=694724 Reproducer