[Secure-testing-team] Bug#584037: prosper: Security bugs in ghostscript

Paul Szabo paul.szabo at sydney.edu.au
Tue Jun 1 01:21:06 UTC 2010


Package: prosper
Version: 1.00.4+cvs.2007.05.01-4
Severity: grave
Tags: security
Justification: user security hole


Please note remote execute-any-code security bugs in ghostscript:

  http://bugs.debian.org/583183

This package depends on ghostscript, and may be affected. Please
evaluate the security of this package, and fix if needed.

Thanks,

Paul Szabo   psz at maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia


-- System Information:
Debian Release: 5.0.4
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: i386 (i686)

Kernel: Linux 2.6.26-pk03.17-svr (SMP w/8 CPU cores)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/bash

Versions of packages prosper depends on:
ii  ghostscript       8.62.dfsg.1-3.2lenny1  The GPL Ghostscript PostScript/PDF
ii  tex-common        1.11.3                 common infrastructure for building
ii  texlive-latex-bas 2007.dfsg.2-1~lenny2   TeX Live: Basic LaTeX packages
ii  texlive-latex-rec 2007.dfsg.2-1~lenny2   TeX Live: LaTeX recommended packag
ii  texlive-pstricks  2007.dfsg.17-1~lenny02 TeX Live: PSTricks packages

prosper recommends no packages.

Versions of packages prosper suggests:
ii  evince [postscript 2.22.2-4~lenny1       Document (postscript, pdf) viewer
ii  ghostscript [posts 8.62.dfsg.1-3.2lenny1 The GPL Ghostscript PostScript/PDF
ii  gv [postscript-vie 1:3.6.5-2             PostScript and PDF viewer for X
ii  kghostview [postsc 4:3.5.9-3+lenny3      PostScript viewer for KDE
ii  kpdf [pdf-viewer]  4:3.5.9-3+lenny3      PDF viewer for KDE
ii  xpdf-reader [pdf-v 3.02-1.4+lenny2       Portable Document Format (PDF) sui
ii  xpdf-utils [pdf-vi 3.02-1.4+lenny2       Portable Document Format (PDF) sui

-- no debconf information





More information about the Secure-testing-team mailing list