bug-ghostscript
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

GNU GhostScript 7.05 comes with broken security "features"


From: David Kastrup
Subject: GNU GhostScript 7.05 comes with broken security "features"
Date: Mon, 8 Jul 2002 13:07:42 +0200

This was already available in 6.54 or so, and it is close to
impossible to find a bug reporting address for GNU GhostScript.

Basically,
save .setsafe restore

is _not_ a noop with regard to security settings: it irretrievably
sets the secure operation mode.  This renders the .runandhide
operator ridiculous.

GNU GhostScript got this wrong when it first backported this
functionality from 7.03 AFPL GhostScript, and it seemingly still
contains the broken backport in spite of being based off AFPL
GhostScript 7.04 or so.

This makes security management for persistent sessions (like in
GhostView, or in preview-latex) impossible.

With preview-latex, I will have to implement checking the version
number and specifically disabling security for GhostScript 7.05.
Please make sure that I will not have to do junk like that for future
versions as well.

Thanks,

-- 
David Kastrup, Kriemhildstr. 15, 44793 Bochum
Email: address@hidden



reply via email to

[Prev in Thread] Current Thread [Next in Thread]