Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <SHcYHexZFIPEzxu783h1FvPmnsUAwkTcsBunOplth1OaHsV-kE1uNS6roHC9sojsMJxQE2yOQoj-BBCc2qWNdb09Yrb-rwTVu1nAJgT7ZO0=@protonmail.ch>
Date: Thu, 18 Oct 2018 13:25:29 +0000
From: Jordan Glover <Golden_Miller83@...tonmail.ch>
To: Tavis Ormandy <taviso@...gle.com>
Cc: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>
Subject: Re: Re: ghostscript: 1Policy operator gives access to .forceput CVE-2018-18284

‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐
On Thursday, October 18, 2018 2:32 PM, Tavis Ormandy <taviso@...gle.com> wrote:

> On Thu, Oct 18, 2018 at 3:51 AM Jordan Glover <Golden_Miller83@...tonmail.ch> wrote:
>
>> Do you know if upstream is going to make new release soon or distros should take the
>> pain and backport all of those themselves?
>
> AFAIK upstream only makes quarterly releases, so I think you need to backport.
>
> Tavis.

In normal, boring times yes but 9.25 was available just 10 days after 9.24 as urgent security
release and it seems it was still not enough.

Jordan

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.