[SECURITY] Fedora 12 Update: gv-3.7.1-1.fc12

updates at fedoraproject.org updates at fedoraproject.org
Thu Jul 8 18:12:48 UTC 2010


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-10660
2010-07-01 18:09:13
--------------------------------------------------------------------------------

Name        : gv
Product     : Fedora 12
Version     : 3.7.1
Release     : 1.fc12
URL         : http://www.gnu.org/software/gv/
Summary     : A X front-end for the Ghostscript PostScript(TM) interpreter
Description :
GNU gv is a user interface for the Ghostscript PostScript(TM) interpreter.
Gv can display PostScript and PDF documents on an X Window System.

--------------------------------------------------------------------------------
Update Information:

- Update to 3.7.1 to fix CVE-2010-2055 and CVE-2010-2056  - Disable
international support to avoid segfault on exit
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jun 28 2010 Orion Poplawski <orion at cora.nwra.com> 3.7.1-1
- Update to 3.7.1
- Disable international support to avoid segfault on exit until
  bug 587349 is fixed
* Thu Jun  3 2010 Orion Poplawski <orion at cora.nwra.com> 3.6.91-1
- Update to 3.6.91 to fix CVE-2010-2055 and CVE-2010-2056
* Mon Apr 26 2010 Orion Poplawski <orion at cora.nwra.com> 3.6.9-1
- Update to 3.6.9
* Tue Mar  2 2010 Orion Poplawski <orion at cora.nwra.com> 3.6.8-2
- Ship icon, update desktop file
* Mon Dec 28 2009 Orion Poplawski <orion at cora.nwra.com> 3.6.8-1
- Update to 3.6.8
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #599621 - CVE-2010-2056 gv: Insecure (predictable) temporary file use
        https://bugzilla.redhat.com/show_bug.cgi?id=599621
  [ 2 ] Bug #599564 - CVE-2010-2055 GhostScript: Honors files present in cwd at startup
        https://bugzilla.redhat.com/show_bug.cgi?id=599564
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update gv' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list