Your message dated Tue, 30 Oct 2007 20:52:17 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#447188: fixed in ghostscript 8.61.dfsg.1~svn8187-2
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: ghostscript
Severity: grave
Tags: security patch

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for ghostscript.

CVE-2007-2721[0]:
| The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer
| JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted
| attackers to cause a denial of service (crash) and possibly corrupt
| the heap via malformed image files, as originally demonstrated using
| imagemagick convert.

If you fix this vulnerability please also include the CVE id
in your changelog entry.

This vulnerability is present in the embedded copy of 
jasper.

See patch on: http://ghostscript.com/pipermail/gs-cvs/2007-October/007877.html

For further information:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2721

Kind regards
Nico

-- 
Nico Golde - http://ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgpxanZhSYScM.pgp
Description: PGP signature


--- End Message ---
--- Begin Message ---
Source: ghostscript
Source-Version: 8.61.dfsg.1~svn8187-2

We believe that the bug you reported is fixed in the latest version of
ghostscript, which is due to be installed in the Debian FTP archive:

ghostscript-doc_8.61.dfsg.1~svn8187-2_all.deb
  to pool/main/g/ghostscript/ghostscript-doc_8.61.dfsg.1~svn8187-2_all.deb
ghostscript-x_8.61.dfsg.1~svn8187-2_i386.deb
  to pool/main/g/ghostscript/ghostscript-x_8.61.dfsg.1~svn8187-2_i386.deb
ghostscript_8.61.dfsg.1~svn8187-2.diff.gz
  to pool/main/g/ghostscript/ghostscript_8.61.dfsg.1~svn8187-2.diff.gz
ghostscript_8.61.dfsg.1~svn8187-2.dsc
  to pool/main/g/ghostscript/ghostscript_8.61.dfsg.1~svn8187-2.dsc
ghostscript_8.61.dfsg.1~svn8187-2_i386.deb
  to pool/main/g/ghostscript/ghostscript_8.61.dfsg.1~svn8187-2_i386.deb
gs-afpl_8.61.dfsg.1~svn8187-2_all.deb
  to pool/main/g/ghostscript/gs-afpl_8.61.dfsg.1~svn8187-2_all.deb
gs-aladdin_8.61.dfsg.1~svn8187-2_all.deb
  to pool/main/g/ghostscript/gs-aladdin_8.61.dfsg.1~svn8187-2_all.deb
gs-common_8.61.dfsg.1~svn8187-2_all.deb
  to pool/main/g/ghostscript/gs-common_8.61.dfsg.1~svn8187-2_all.deb
gs-esp_8.61.dfsg.1~svn8187-2_all.deb
  to pool/main/g/ghostscript/gs-esp_8.61.dfsg.1~svn8187-2_all.deb
gs-gpl_8.61.dfsg.1~svn8187-2_all.deb
  to pool/main/g/ghostscript/gs-gpl_8.61.dfsg.1~svn8187-2_all.deb
gs_8.61.dfsg.1~svn8187-2_all.deb
  to pool/main/g/ghostscript/gs_8.61.dfsg.1~svn8187-2_all.deb
libgs-dev_8.61.dfsg.1~svn8187-2_i386.deb
  to pool/main/g/ghostscript/libgs-dev_8.61.dfsg.1~svn8187-2_i386.deb
libgs8_8.61.dfsg.1~svn8187-2_i386.deb
  to pool/main/g/ghostscript/libgs8_8.61.dfsg.1~svn8187-2_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Masayuki Hatta (mhatta) <[EMAIL PROTECTED]> (supplier of updated ghostscript 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Wed, 31 Oct 2007 02:27:38 +0900
Source: ghostscript
Binary: gs-esp libgs-dev ghostscript-x gs-common libgs8 ghostscript gs-gpl gs 
gs-afpl gs-aladdin ghostscript-doc
Architecture: source all i386
Version: 8.61.dfsg.1~svn8187-2
Distribution: unstable
Urgency: low
Maintainer: Masayuki Hatta (mhatta) <[EMAIL PROTECTED]>
Changed-By: Masayuki Hatta (mhatta) <[EMAIL PROTECTED]>
Description: 
 ghostscript - The GPL Ghostscript PostScript/PDF interpreter
 ghostscript-doc - The GPL Ghostscript PostScript/PDF interpreter - 
Documentation
 ghostscript-x - The GPL Ghostscript PostScript/PDF interpreter - X Display 
suppor
 gs         - Transitional package
 gs-afpl    - Transitional package
 gs-aladdin - Transitional package
 gs-common  - Transitional package
 gs-esp     - Transitional package
 gs-gpl     - Transitional package
 libgs-dev  - The Ghostscript PostScript Library - Development Files
 libgs8     - The Ghostscript PostScript/PDF interpreter Library
Closes: 428055 444467 444468 446825 446927 447188
Changes: 
 ghostscript (8.61.dfsg.1~svn8187-2) unstable; urgency=low
 .
   * Maintainer upload, acknowledged NMU - closes: #447188
   * Made all dummy packages depend on ghostscript AND ghostscript-x, so
     their nominal "functionality" should virtually be the equivalent to
     the former gs|gs-gpl|gs-esp|gs-afpl packages - closes: #446825
   * Revised debian/copyright - closes: #444468, #444467
   * debian/rules: Clean files from package ghostscript which are moved to
     ghostscript-doc on i386 (where arch-all packages are built). On all
     non-i386 platforms the files remained in the main package, which
     causes file conflicts and unnecessary package growth - closes: #446927
     (fix from Ubuntu)
   * debian/patches/06_libpaper_support.dpatch: Added missing "#include
     <paper.h>", this made Ghostscript not working at all on IA64 - closes:
     #428055 (fix from Ubuntu)
Files: 
 b4109c616c25ba49989f27713bd3c1ac 1103 text optional 
ghostscript_8.61.dfsg.1~svn8187-2.dsc
 5eac89ea4ab6881c2ab03583afa99e0d 45969 text optional 
ghostscript_8.61.dfsg.1~svn8187-2.diff.gz
 0883a2e8b84a3ecb1155b3744d706b5e 23308 text extra 
gs_8.61.dfsg.1~svn8187-2_all.deb
 65d971afaf859ef5d655f703f467eb5f 23316 text extra 
gs-esp_8.61.dfsg.1~svn8187-2_all.deb
 e34fcb2c257348243b55934c909f2af2 23312 text extra 
gs-gpl_8.61.dfsg.1~svn8187-2_all.deb
 ad58601668cff1ab47e655d6987eb9f1 23316 text extra 
gs-afpl_8.61.dfsg.1~svn8187-2_all.deb
 d920416a61f678b862f709b9b616278c 23322 text extra 
gs-aladdin_8.61.dfsg.1~svn8187-2_all.deb
 c00acb3f8e963a7595d5e1c9c7b38ef9 23326 text extra 
gs-common_8.61.dfsg.1~svn8187-2_all.deb
 acf45210774d056738c2493972c99f68 2672614 doc optional 
ghostscript-doc_8.61.dfsg.1~svn8187-2_all.deb
 1e54f6f062eb0e5b30d2ae7997b54c4e 783236 text optional 
ghostscript_8.61.dfsg.1~svn8187-2_i386.deb
 babce87ed1d218a87232a0b0938916d2 55722 text optional 
ghostscript-x_8.61.dfsg.1~svn8187-2_i386.deb
 ed255fa9222f3f0f5b9286dd4e324e37 2185922 libs optional 
libgs8_8.61.dfsg.1~svn8187-2_i386.deb
 1e475c15615f61bd0638eea1a3b265ad 30920 libdevel optional 
libgs-dev_8.61.dfsg.1~svn8187-2_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFHJ487y2+jQOcHWlQRArkSAJ0dc8Z30Ejnr6xngQ9y71+EhBTjVQCdHaxB
fHlooHIgW1VMsGog8YQSANQ=
=FBeY
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to