From owner-freebsd-ports-bugs@FreeBSD.ORG Sun Mar 2 12:20:03 2008 Return-Path: Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 100D2106566B for ; Sun, 2 Mar 2008 12:20:03 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 0509C8FC2E for ; Sun, 2 Mar 2008 12:20:03 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.14.2/8.14.2) with ESMTP id m22CK2sP005085 for ; Sun, 2 Mar 2008 12:20:02 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.2/8.14.1/Submit) id m22CK2IO005084; Sun, 2 Mar 2008 12:20:02 GMT (envelope-from gnats) Date: Sun, 2 Mar 2008 12:20:02 GMT Message-Id: <200803021220.m22CK2IO005084@freefall.freebsd.org> To: freebsd-ports-bugs@FreeBSD.org From: bf Cc: Subject: Re: ports/121283: [PATCH]print/ghostscript-gpl: fix security hole in 8.61 X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: bf List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 02 Mar 2008 12:20:03 -0000 The following reply was made to PR ports/121283; it has been noted by GNATS. From: bf To: bug-followup@FreeBSD.org Cc: Subject: Re: ports/121283: [PATCH]print/ghostscript-gpl: fix security hole in 8.61 Date: Sun, 2 Mar 2008 04:14:54 -0800 (PST) I should also mention that versions of ghostscript prior to 8.61 may suffer from the remote security vulnerability CVE-2007-2721 in the bundled jasper code. See: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2721 This vulnerability has been fixed in the latest ghostscript 8.61 source code tarballs, using a fix from: http://www.mail-archive.com/debian-bugs-rc@lists.debian.org/msg118235.html This should probably also be noted in vuxml. ____________________________________________________________________________________ Looking for last minute shopping deals? Find them fast with Yahoo! Search. http://tools.search.yahoo.com/newsearch/category.php?category=shopping