--- - branch: MAIN date: Thu Aug 23 14:52:23 UTC 2018 files: - new: '1.247' old: '1.246' path: pkgsrc/graphics/ImageMagick/Makefile pathrev: pkgsrc/graphics/ImageMagick/Makefile@1.247 type: modified - new: '1.192' old: '1.191' path: pkgsrc/graphics/ImageMagick/distinfo pathrev: pkgsrc/graphics/ImageMagick/distinfo@1.192 type: modified - new: '1.2' old: '1.1' path: pkgsrc/graphics/ImageMagick/patches/patch-config_policy.xml pathrev: pkgsrc/graphics/ImageMagick/patches/patch-config_policy.xml@1.2 type: modified id: 20180823T145223Z.cb028377c9739d16eee6f8b92d73861fbf220d3e log: | ImageMagick: Also block PS2 and PS3 coders in policy.xml At least when reading PS2 and PS3 files via `convert PS2: ' and `convert PS3: ' gslib/ghostscript will be invoked and hence subject to VU#332928. Pointed out by Bob Friesenhahn via oss-security@ ML (and follow up from VU#332928 update). module: pkgsrc subject: 'CVS commit: pkgsrc/graphics/ImageMagick' unixtime: '1535035943' user: leot