Bug#583183: [Pkg-cups-devel] Bug#584003: cups-pdf: Security bugs in ghostscript

2010-06-01 Thread paul . szabo
Dear Martin-Eric, > ... We already call -dSAFER and drop privileges early, so we're > already protected as it is. Closing. Sorry, you seem to misunderstand: this bug is (more-or-less) about the need to use the -P- also, as well as -dSAFER, to be protected. Is cups-pdf "part of" cups? In that cas

Bug#583183: [Pkg-cups-devel] Bug#584003: cups-pdf: Security bugs in ghostscript

2010-06-01 Thread Martin-Éric Racine
On Tue, Jun 1, 2010 at 4:06 AM, Paul Szabo wrote: > Package: cups-pdf > Severity: grave > Tags: security > Justification: user security hole > > > Please note remote execute-any-code security bugs in ghostscript: > >  http://bugs.debian.org/583183 > > This package depends on ghostscript, and may b