diff options
author | Ray Johnston <ray.johnston@artifex.com> | 2019-10-21 15:12:57 -0700 |
---|---|---|
committer | Ray Johnston <ray.johnston@artifex.com> | 2019-10-22 07:55:58 -0700 |
commit | a7fe4b47d438c78af0fc03adf030d465cfe0ba4f (patch) | |
tree | 50b6580404081c94b380f931e9e813ac2c4672f5 /base/cal.mak | |
parent | b4521b891de48d7f62be739d02749c4aeca2fde8 (diff) | |
download | ghostpdl-a7fe4b47d438c78af0fc03adf030d465cfe0ba4f.tar.gz |
Apply DOPS to "bare" PS operator in PDF's
PDF 1.2 defined a PS operator that could be used in streams to execute
PostScript. This went away with PDF 1.3 2nd edition spec., but Ghostscript
retained the functionality. In commit e7086fc6 we disabled the execution
of Subtype /PS streams (requiring -dDOPS to enable them), but the "PS"
operator, that sends PostScript strings to the underlying Postscript
interpreter remained unaffected, leading to Bug 700176 exploit.
This patch also disables the "PS" operator unless -dDOPS is specified.
Using -dDOPS is *NOT* recommended, although the fixes for Bug700176
should prevent that particular exploit.
Diffstat (limited to 'base/cal.mak')
0 files changed, 0 insertions, 0 deletions