Re: Xpdf Integer overflow

2009-10-17 Thread Florian Weimer
* Michael Gilbert:

 On Fri, 16 Oct 2009 20:15:50 +0300, Henri Salo wrote:
 Is update for Xpdf-vulnerability coming soon for this issue:
 
 http://securityreason.com/securityalert/6674

 this issue was not disclosed responsibly

Huh?  Why do you think so?

As far as I can see, a reasonable disclosure protocol was followed.


-- 
To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Xpdf Integer overflow

2009-10-16 Thread Henri Salo
Is update for Xpdf-vulnerability coming soon for this issue:

http://securityreason.com/securityalert/6674

---
Henri Salo


-- 
To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Re: Xpdf Integer overflow

2009-10-16 Thread Michael Gilbert
On Fri, 16 Oct 2009 20:15:50 +0300, Henri Salo wrote:
 Is update for Xpdf-vulnerability coming soon for this issue:
 
 http://securityreason.com/securityalert/6674

this issue was not disclosed responsibly, and we have just started
tracking the problem.  you can follow bug #551287.

mike


-- 
To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org