Xpdf Integer overflow

View: New views
3 Messages — Rating Filter:   Alert me  

Xpdf Integer overflow

by Henri Salo-5 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Is update for Xpdf-vulnerability coming soon for this issue:

<http://securityreason.com/securityalert/6674>

---
Henri Salo


--
To UNSUBSCRIBE, email to debian-security-REQUEST@...
with a subject of "unsubscribe". Trouble? Contact listmaster@...


Re: Xpdf Integer overflow

by Michael Gilbert :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On Fri, 16 Oct 2009 20:15:50 +0300, Henri Salo wrote:
> Is update for Xpdf-vulnerability coming soon for this issue:
>
> <http://securityreason.com/securityalert/6674>

this issue was not disclosed responsibly, and we have just started
tracking the problem.  you can follow bug #551287.

mike


--
To UNSUBSCRIBE, email to debian-security-REQUEST@...
with a subject of "unsubscribe". Trouble? Contact listmaster@...


Re: Xpdf Integer overflow

by Florian Weimer :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

* Michael Gilbert:

> On Fri, 16 Oct 2009 20:15:50 +0300, Henri Salo wrote:
>> Is update for Xpdf-vulnerability coming soon for this issue:
>>
>> <http://securityreason.com/securityalert/6674>
>
> this issue was not disclosed responsibly

Huh?  Why do you think so?

As far as I can see, a reasonable disclosure protocol was followed.


--
To UNSUBSCRIBE, email to debian-security-REQUEST@...
with a subject of "unsubscribe". Trouble? Contact listmaster@...