@taviso somewhat surprising ghostscript seems pretty resistant to fuzzing, not crashing easily
-
-
Ah, it looks like 3/4 of the crashes found with the Ubuntu version are fixed in the git version of ghostscript.
-
2 hours into a single-vm fuzzing campaign against the latest git version of ghostscript.pic.twitter.com/kh1P7gP6id
- 5 more replies
New conversation -
-
-
I'm starting to think the only solution is adding seccomp-bpf sandboxing to old gpl gs (gs is just a wrapper around libgs).
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
it's pretty common to have stale code in the Ubuntu package sources. Always best to go with git IME
-
Right. But also, a security issue affecting a supported version of Ubuntu is also noteworthy.
- 3 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.