[Secure-testing-team] Bug#584056: mgetty-fax: Security bugs in ghostscript

Paul Szabo paul.szabo at sydney.edu.au
Tue Jun 1 01:31:45 UTC 2010


Package: mgetty-fax
Severity: grave
Tags: security
Justification: user security hole


Please note remote execute-any-code security bugs in ghostscript:

  http://bugs.debian.org/583183

This package suggests ghostscript, and may be affected. Please
evaluate the security of this package, and fix if needed.

Thanks,

Paul Szabo   psz at maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia


-- System Information:
Debian Release: 5.0.4
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: i386 (i686)

Kernel: Linux 2.6.26-pk03.17-svr (SMP w/8 CPU cores)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/bash

Versions of packages mgetty-fax depends on:
ii  cron                     3.0pl1-105      management of regular background p
ii  libc6                    2.7-18lenny2    GNU C Library: Shared libraries
pn  mgetty                   <none>          (no description available)
ii  perl [perl5]             5.10.0-19lenny2 Larry Wall's Practical Extraction 

Versions of packages mgetty-fax recommends:
ii  metamail                      2.7-54     implementation of MIME

Versions of packages mgetty-fax suggests:
ii  debianutils        2.30                  Miscellaneous utilities specific t
ii  ghostscript-x [gs- 8.62.dfsg.1-3.2lenny1 The GPL Ghostscript PostScript/PDF
ii  gs                 8.62.dfsg.1-3.2lenny1 Transitional package
ii  gs-aladdin         8.62.dfsg.1-3.2lenny1 Transitional package
pn  mgetty-viewfax     <none>                (no description available)
ii  netpbm [pnmtopng]  2:10.0-12+lenny1      Graphics conversion tools





More information about the Secure-testing-team mailing list