Bug#1041836: libc6 2.36-9+deb12u1 double free abort

2023-08-10 Thread Paul Szabo
quot;, but did not help to fix the issue. I may try to change physical RAM modules, not sure whether have suitable replacements. Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia

Bug#1041836: root unable to write un-owned

2023-08-09 Thread Paul Szabo
Bummer. This last "echo x > /tmp/x" issue is probably the result of protected_regular being set in kernel configs, see https://docs.kernel.org/admin-guide/sysctl/fs.html#id12 Sorry about the noise. (Hangs head in shame.) Cheers, Paul

Bug#1041836: root unable to write un-owned

2023-08-09 Thread Paul Szabo
Another oddity that should never happen: root cannot write file that he does not own. Demonstration (root running bash): root# touch /tmp/x root# ls -l /tmp/x -rw-r--r-- 1 root root 0 Aug 10 09:39 /tmp/x root# echo a > /tmp/x root# chown 2:2 /tmp/x root# ls -l /tmp/x -rw-r--r-- 1

Bug#1041836: libc6 2.36-9+deb12u1 double free abort

2023-08-09 Thread Paul Szabo
Dear Aurelien, I used LD_PRELOAD=libc_malloc_debug.so for MALLOC_CHECK_. With those extra checks (tried all values of MALLOC_CHECK_ from 0 to 20), glibc did not show any errors, suggesting that the bug is not in inetd. The original poster said his issue shows on some hardware only. I observed my

Bug#1041836: libc6 2.36-9+deb12u1 double free abort

2023-08-08 Thread Paul Szabo
ebug.so "fixes" the issue. Hope this helps to find the cause. Cheers, Paul References: http://btorpey.github.io/blog/2019/07/14/memory-checking/ https://www.gnu.org/software/libc/manual/html_node/Heap-Consistency-Checking.html -- Paul Szabo p...@maths.usyd.edu.au www.mat

Bug#988763: rxvt-unicode: Remote(?) code execution via ESC G Q

2021-05-21 Thread Paul Szabo
that come to mind: www.debian.org/security/2003/dsa-380 www.debian.org/security/2009/dsa-1694 bugs.debian.org/511516 Anyway, I solved my problem by "apt purge rxvt-unicode" on all my machines. Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd

Bug#988763: rxvt-unicode: Remote(?) code execution via ESC G Q

2021-05-21 Thread Paul Szabo
disclosure/2021/May/51 (quoted below for completeness), it seems that this is now fixed upstream in version 9.25, maybe they did consider it a bug. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of Sydney

Bug#988763: rxvt-unicode: Remote(?) code execution via ESC G Q

2021-05-19 Thread Paul Szabo
Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia Quoting messasge: From: def To: Date: Sun, 16 May 2021 15:32:48 +0300 Subject: [FD] (u)rxvt terminal (+bash) remoteish code execution 0day #!/usr/bin

Bug#956084: inetutils-telnetd: CVE-2020-10188

2020-04-06 Thread Paul Szabo
or urgent data, because of a buffer overflow involving the netclear and nextitem functions. Seems to me that inetutils contains the same (vulnerable) utility.c functions. Please check. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics

Bug#845393: Pending fixes for bugs in the tomcat8 package

2016-12-02 Thread paul . szabo
ch upgrade). This seems confusing. Would it be worthwhile to handle them both in the same way? Maybe some other things in postinst could get the same treatment. (Simple is easier to keep secure.) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of M

Bug#845393: Pending fixes for bugs in the tomcat8 package

2016-12-01 Thread paul . szabo
, is there a need to set it writable? Is there a need to have these owned by group tomcat8, could they be left as root:root and world-accessible? Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#845393: Pending fixes for bugs in the tomcat8 package

2016-12-01 Thread paul . szabo
from the DEB package, the ownership only to be fixed in postinst? In the current DEB, that directory is not group-writable. Could you kindly explain how this all works. Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics

Bug#845393: Pending fixes for bugs in the tomcat8 package

2016-12-01 Thread paul . szabo
Hmm... I just accused you of being mistaken... but maybe it is I who is wrong. - Now thinking it through again. Cheers, Paul

Bug#845393: Pending fixes for bugs in the tomcat8 package

2016-12-01 Thread paul . szabo
; > https://anonscm.debian.org/cgit/pkg-java/tomcat8.git/commit/?id=02570d6 > > The script still chmods the Catalina directory but this one can't be > replaced by a symlink. You are mistaken. Please re-read the original bug report. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au h

Bug#845393: marked as done (Privilege escalation via upgrade)

2016-12-01 Thread paul . szabo
reopen 845393 thanks Not done. Please fix proper. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#845393: Pending fixes for bugs in the tomcat8 package

2016-12-01 Thread paul . szabo
Dear Emmanuel, > No longer make /etc/tomcat8/Catalina/localhost writable ... The bug depends on "Catalina" being writable; the permissions on "localhost" are irrelevant. Please re-open. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.us

Bug#845385: Privilege escalation via removal

2016-11-30 Thread paul . szabo
tice that the Debian bug contraption does not CC me on messages: just being the submitter does not add you to the CC list, you need to explicitly "subscribe". So I missed a number of intermediate messages. --- Markus wrote previously: > ... Besides all tomcat processes are killed on purge. Where does that happen? I do not think that is true. Neither are any possible setuid-tomcat8 or setgid-tomcat8 files removed. --- Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#845385: Privilege escalation via removal

2016-11-22 Thread paul . szabo
rocesses, also. That might be a "good thing": deluser or delgroup might not "work" with left-over, running processes; and might protect against a race. But really... why do you care about leaving some "dangling" useless object, owned by some long-gone UID or GID?

Bug#845393: Privilege escalation via upgrade

2016-11-22 Thread Paul Szabo
her useful attacks might be to make the objects: /root/.Xauthority /etc/ssh/ssh_host_dsa_key world-readable; or make something (already owned by group tomcat8) group-writable (some "policy" setting maybe?). Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/

Bug#845385: Privilege escalation via removal

2016-11-22 Thread Paul Szabo
the world. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#841257: sendmail: Privilege escalation from group smmsp to (user) root

2016-11-09 Thread paul . szabo
Dear Andreas, > I have a completely untested patch sitting in GIT - do you have a > possibility to test packages built from that? I could replace files, or DEB packages, on some test machines. Do not know whether that testing would be exhaustive: do not know how many features of the sendmail

Bug#841257: sendmail: Privilege escalation from group smmsp to (user) root

2016-10-19 Thread paul . szabo
ines always have a process like: USER PID %CPU %MEMVSZ RSS TTY STAT START TIME COMMAND smmsp 2880 0.0 0.0 11956 3236 ?Ss Oct11 0:00 sendmail: Queue runner@00:10:00 for /var/spool/mqueue-client running. Cheers, Paul Paul Szabo p...@maths.us

Bug#841257: sendmail: Privilege escalation from group smmsp to (user) root

2016-10-18 Thread paul . szabo
Hmm... you may also need to (once) do: chown smmsp /var/run/sendmail/stampdir/reload when adopting my patch. Cheers, Paul

Bug#841257: sendmail: Privilege escalation from group smmsp to (user) root

2016-10-18 Thread Paul Szabo
su smmsp -s /bin/bash -c "touch > $STAMP_DIR/cron_msp"; 912c912 < touch $STAMP_DIR/cron_mta; --- > su smmsp -s /bin/bash -c "touch $STAMP_DIR/cron_mta"; 938c938 < touch

Bug#840685: TOCTOU race condition in initscript on chown'ing JVM_TMP temporary directory (was: Re: Bug#840685: tomcat8: DSA-3670 incomplete)

2016-10-14 Thread paul . szabo
eed for DSA. (Sorry about the noise.) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#840685: tomcat8: DSA-3670 incomplete

2016-10-14 Thread paul . szabo
ymlink, you do the useless "mkdir -p" and you chown; I win. For your test, you took the rm out of your script: you should see /etc being chowned to tomcat8. Please confirm. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#840685: tomcat8: DSA-3670 incomplete

2016-10-14 Thread paul . szabo
in less than a day is not very reasonable, > especially when there are things like the time difference between > Australia and Europe. You can do better, if you try. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#840685: tomcat8: DSA-3670 incomplete

2016-10-14 Thread paul . szabo
whole day... compared to that, Markus replied within the hour to the Debian bug. (But he did not yet reply to my next, private bug/message... seems public messaging works best!) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#840685: tomcat8: DSA-3670 incomplete

2016-10-13 Thread paul . szabo
are appreciated. ... Maybe the security team will understand (recognize, accept) the issue without a PoC. If they reply with such a need, then I will write one. You or they might accept the suggested patch/fix: mkdir without -p, chown with -h. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://

Bug#840685: tomcat8: DSA-3670 incomplete

2016-10-13 Thread Paul Szabo
"chown -h". (This would protect against the above attack.) The script should use plain mkdir without "-p": not needed as we create a single directory, and should not be used to let mkdir return failure. (This may make it safe.) Cheers, Paul Paul Szabo p...@maths.usyd.edu.

Bug#775541: NFS mounts fail at boot after Debian 8.5 upgrade

2016-09-06 Thread paul . szabo
Dear Vincent, > Could you provide a bit more information about the package versions > on your system? > dpkg -l rpcbind nfs-common nfs-kernel-server systemd psz@como:~$ dpkg -l rpcbind nfs-common nfs-kernel-server systemd Desired=Unknown/Install/Remove/Purge/Hold |

Bug#775541: NFS mounts fail at boot after Debian 8.5 upgrade

2016-08-19 Thread paul . szabo
=rpcbind.service instead? Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#803013: systemd should not destroy application created cgroups

2015-10-25 Thread Paul Szabo
t-get dist-upgrade" sequences, and "start anacron" happens nightly. (Some other systemd commands may also affect.) I propose the attached patch to avoid the issue. This patch seems to work well for me. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.

Bug#684645: liblockfile1: Order of fcntl and dotlock in maillock

2012-10-27 Thread paul . szabo
: *** [debian/stamp-patched] Error 1 dpkg-buildpackage: error: debian/rules build-arch gave error exit status 2 Can you give me a hint on what I am doing wrong? Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University

Bug#648941: /usr/lib/sm.bin/mail.local: Uses flock, not fcntl

2012-08-12 Thread paul . szabo
, /var/mail/psz.lock) = 0 open(/var/mail/psz, O_WRONLY|O_APPEND) = 4 fcntl64(4, F_SETLKW, {type=F_WRLCK, whence=SEEK_CUR, start=0, len=0}) = 0 which seems the wrong order. Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics

Bug#648941: /usr/lib/sm.bin/mail.local: Uses flock, not fcntl

2012-08-12 Thread paul . szabo
or maybe elsewhere. Assuming the latter, I will now submit a new bug against liblockfile1. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc

Bug#684645: liblockfile1: Order of fcntl and dotlock in maillock

2012-08-12 Thread Paul Szabo
://bugs.debian.org/648941 also. Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: wheezy/sid APT prefers testing APT policy: (500, 'testing') Architecture

Bug#684645: /usr/lib/sm.bin/mail.local: Order of fcntl and dotlock in maillock

2012-08-12 Thread paul . szabo
, in the initial report of http://bugs.debian.org/648941 . Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject

Bug#648941: /usr/lib/sm.bin/mail.local: Uses flock, not fcntl

2012-08-12 Thread paul . szabo
Dear Tobias, I submitted http://bugs.debian.org/684645 against liblockfile1. But then I realized that liblockfile is fine and that the bug must be within mail.local sources, so I re-assigned that bug to sendmail-bin. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http

Bug#648941: /usr/lib/sm.bin/mail.local: Uses flock, not fcntl

2011-11-16 Thread Paul Szabo
files, and in fact observed on rare occasions. Please see http://bugs.debian.org/513298 also. Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- Package-specific info: Ouput

Bug#621691: libxslt1.1: XML Security Library xslt.c Arbitrary File Access

2011-04-07 Thread Paul Szabo
not use XML so did not verify.) Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.8 APT prefers oldstable APT policy: (500, 'oldstable

Bug#621423: /usr/bin/xrdb: xdmcp rogue hostname security

2011-04-06 Thread Paul Szabo
: all : allow However I notice that gdm uses IP address only, not hostname when evaluating hosts.allow lines, so I wonder about the effectiveness of this protection. How would I test whether my setup is vulnerable? Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz

Bug#602333: /usr/bin/fusermount: fusermount allows unmount any filesystem

2011-01-19 Thread paul . szabo
Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#584653: RC bugs in upcoming stable

2010-12-01 Thread paul . szabo
and #584663 are marked Fixed in version 9.00~dfsg-1. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject

Bug#584653: ghostscript: does not honor -P- option

2010-11-27 Thread paul . szabo
Dear Mehdi, We prefer targeted fixes ... ... we won't be able to review [gs 9.00] or accept it ... Supposing that those targeted fixes may not happen. Would you then release gs 8.71 with a grave (= RC) bug? Or would you drop gs, or delay squeeze? I am genuinely curious. Thanks, Paul Paul

Bug#602333: /usr/bin/fusermount: fusermount allows unmount any filesystem

2010-11-22 Thread paul . szabo
Ubuntu has now added the reference CVE-2010-3879 to https://bugs.launchpad.net/bugs/670622 and marked in confirmed. Other interesting references: https://bugzilla.redhat.com/show_bug.cgi?id=651183 https://bugzilla.novell.com/show_bug.cgi?id=651598 Cheers, Paul Paul Szabo p...@maths.usyd.edu.au

Bug#584663: imagemagick uses gs without -P-

2010-11-22 Thread paul . szabo
, no need for more mass bug filing.) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe

Bug#584663: imagemagick uses gs without -P-

2010-11-22 Thread paul . szabo
. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Bug#584653: Patch to close CVE-2010-2055

2010-11-20 Thread paul . szabo
, to have -dSAFER as default? Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble

Bug#584653: Patch to close CVE-2010-2055

2010-11-20 Thread paul . szabo
, ghostscript is OK. 2 - Version 8.71 has a grave i.e. RC bug, must upgrade to 9.00. (or something else)? Your reply suggests that they will choose 2, in effect assuring me that this will make it into squeeze. Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz

Bug#584663: Bug#584653: Patch to close CVE-2010-2055

2010-11-20 Thread paul . szabo
-v '/(usr|etc|var|lib)/' The first two are identical: attempt to load various things from proper places only, not current dir. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#602333: /usr/bin/fusermount: fusermount allows unmount any filesystem

2010-11-03 Thread Paul Szabo
attached below. Cheers, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.6 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel

Bug#602333: /usr/bin/fusermount: fusermount allows unmount any filesystem

2010-11-03 Thread paul . szabo
to this issue. I would expect DSA-1989 to have been adopted and fixed by Ubuntu, where the original poster says he found the issue. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#584653: Debian NMU ghostscript

2010-10-25 Thread paul . szabo
-. (These bugs are related. I had tried to report them as the one thing bug 583183, but that did not get very far...) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE

Bug#584663: ghostscript: insecure defaults for path searching

2010-08-12 Thread paul . szabo
for understanding. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble

Bug#584663: ghostscript: insecure defaults for path searching

2010-08-11 Thread paul . szabo
. (Not much time left after useless arguments...) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject

Bug#592569: ghostscript: Please make -dSAFER the default

2010-08-10 Thread Paul Szabo
=584663#55 Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.5 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel

Bug#584663: ghostscript: insecure defaults for path searching

2010-08-10 Thread paul . szabo
=583183#42 and that it will not be rudely and wrongly closed like #583183 was in http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=91;bug=583183 Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of Sydney

Bug#584663: ghostscript: insecure defaults for path searching

2010-08-09 Thread paul . szabo
Dear Moritz, I think we should change the default to -dSAFER, but postpone it for Squeeze+1. That is something which should be thoroughly tested in unstable for a few months. Thanks. Will this now be taken care of, or should I open another grave bug against ghostscript? Thanks, Paul Paul

Bug#584663: ghostscript: insecure defaults for path searching

2010-08-08 Thread paul . szabo
that upstream finally seems to have made -P- the default, after all the ugly shouting (now deleted) saying WONTFIX in http://bugs.ghostscript.com/show_bug.cgi?id=691316 http://bugs.ghostscript.com/show_bug.cgi?id=691339 --- Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http

Bug#584653: ghostscript: does not honor -P- option

2010-08-08 Thread paul . szabo
I wonder if this is now fixed upstream: http://bugs.ghostscript.com/show_bug.cgi?id=691350#c19 Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian

Bug#584663: ghostscript: insecure defaults for path searching

2010-08-07 Thread paul . szabo
Yes. All those who wish to call gs in unsafe ways, can (should!) explicitly use -P (and -NOSAFER). You surely ment -dNOSAFER, not -NOSAFEE. Sorry, wrote that carelessly from memory, without consulting the oh-so-useless Debian man page. Yes, I did mean -dNOSAFER. Cheers, Paul Paul Szabo p

Bug#584663: ghostscript: insecure defaults for path searching

2010-08-06 Thread paul . szabo
://bugs.ghostscript.com/show_bug.cgi?id=691350#c18 ? Is not that search only in /usr/share/ghostscript idea even more restrictive than -P- which excludes . only? Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University

Bug#584667: Bug#583183: CVE-2010-2055

2010-07-13 Thread paul . szabo
://bugzilla.redhat.com/show_bug.cgi?id=599564 Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject

Bug#584022: page-crunch: Security bugs in ghostscript

2010-06-03 Thread paul . szabo
upcoming) gs bugs. Hope this helps... Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject

Bug#583183: Scribus -dPARANOIDSAFER

2010-06-03 Thread paul . szabo
it is unsafe with all those options, but those are being worked on upstream and should make it into Debian, eventually.) Cheers, Paul (noting I am no gs expert, nor Debian maintainer) Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University

Bug#584001: courier-faxmail: Security bugs in ghostscript

2010-06-02 Thread paul . szabo
not know if ghostscript will ever be fixed in any sense. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject

Bug#584015: ijsgutenprint: Security bugs in ghostscript

2010-06-02 Thread paul . szabo
starting this weekend, and will not have computer access during that time. If the issue is still outstanding in July then I will work on it again, and may ask for your help then. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics

Bug#584061: recoll: Security bugs in ghostscript

2010-06-01 Thread paul . szabo
of foomatic-filters apparently. But in essence, because I was asked to do so: please see http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583183#42 and thereabouts. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics

Bug#584026: printconf: Security bugs in ghostscript

2010-06-01 Thread paul . szabo
Dear Chris, I now see what tripped me up: in my Packages file, printconf depends on ghostscript, but foomatic-filters doesn't. Maybe that could be fixed? Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University

Bug#584013: hyperlatex: Security bugs in ghostscript

2010-06-01 Thread paul . szabo
in the hyperlatex source package in bin/ps2image, for the record. Yes, that probably should fix things. (Right now things are still unsafe even with those options, but I expect gs to be able to fix the remaining bugs.) Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au

Bug#584001: courier-faxmail: Security bugs in ghostscript

2010-06-01 Thread paul . szabo
Dear Racke, What kind of fixes do you have in mind? Please add the -P- option to all $GS invocations. Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email

Bug#584062: sdf: Security bugs in ghostscript

2010-06-01 Thread paul . szabo
Dear Colin, Your explanation shows you are not directly responsible (maybe not vulnerable at all), and can close the bug. Thanks for investigating, sorry about the noise. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics

Bug#584001: courier-faxmail: Security bugs in ghostscript

2010-06-01 Thread paul . szabo
Dear Racke, ... I just wonder why this option isn't mentioned in the gs manpage. Good question. Maybe report as a bug to ghostscript? Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#584052: kdelibs4c2a: Security bugs in ghostscript

2010-06-01 Thread paul . szabo
Dear Sune, I agree with you. I suggested to gs that it should be secure-by-default, but they refused. Please do convince them... In the meantime, maybe you want to fix your use of that crappy gs. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School

Bug#584013: hyperlatex: Security bugs in ghostscript

2010-06-01 Thread paul . szabo
the contortions that gv is going to to protect themselves in http://bugs.debian.org/583316 .) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc-requ

Bug#583995: advi-examples: Security bugs in ghostscript

2010-06-01 Thread paul . szabo
Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#583995: advi-examples: Security bugs in ghostscript

2010-06-01 Thread paul . szabo
Dear Mehdi, On a side note, you should check ... In case, it isn't obvious: I already read 583183 before closing and I explained why advi-examples isn't open to such flaws. I see: that comment was not directed at me. Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http

Bug#583183: [Pkg-cups-devel] Bug#584003: cups-pdf: Security bugs in ghostscript

2010-06-01 Thread paul . szabo
you may be safe because of chdir(/), see http://bugs.debian.org/584002 . Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to debian-bugs-rc-requ

Bug#584015: ijsgutenprint: Security bugs in ghostscript

2010-06-01 Thread paul . szabo
package dependencies. Responses to the various bugs show that no-one was aware of -P-, many still stubbornly say I use -dSAFER thus am safe. I am not sure now if there was anyone without -dSAFER. Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School

Bug#583316: Running gs in a safe directory.

2010-05-31 Thread paul . szabo
/lib/gv/safe-gs-workdir is created. I would prefer to check it actually is empty... pure paranoia, is root-owned so is unlikely to change. Name it please-keep-empty maybe? Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics

Bug#583183: /usr/bin/gs: Insecure gs initialization

2010-05-31 Thread paul . szabo
GS_EXECUTABLE=gs Surely that last line is meant to be GS_EXECUTABLE=$gs as is on current gs distribution. But even then is badly written, should probably be: GS_EXECUTABLE=gs gs=`dirname $0`/$GS_EXECUTABLE if test -x $gs; then GS_EXECUTABLE=$gs fi --- Cheers, Paul Paul Szabo p

Bug#583994: advi: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel

Bug#583995: advi-examples: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
, and fix if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686

Bug#583996: asymptote: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel

Bug#583997: bmv: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel: Linux

Bug#583998: c2050: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel

Bug#584000: capisuite: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel

Bug#584002: cups: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel

Bug#584001: courier-faxmail: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
, and fix if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686

Bug#584003: cups-pdf: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel

Bug#584004: epix1: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel

Bug#584005: epstool: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel

Bug#584006: fbi: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel: Linux

Bug#584007: fig2ps: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel

Bug#584008: flpsed: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel

Bug#584009: hevea: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel

Bug#584010: hpijs: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel

Bug#584011: hylafax-client: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
, and fix if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686

Bug#584012: hylafax-server: Security bugs in ghostscript

2010-05-31 Thread Paul Szabo
, and fix if needed. Thanks, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686

  1   2   3   >