On Fri, 28 Dec 2001, C. L. McAvaney wrote:

>
>     Date:       Wed, 26 Dec 2001 14:24:30 -0800 (PST)
>     From:       Patrick Powell <[EMAIL PROTECTED]>
>
>   > Did you run the test that was in the README?  I think that this
>   > problem was solved in AFPL Ghostscript and it works correctly
>   > now WITHOUT the patch.
> Yep, I ran those tests (without and with the modifications you suggested),
> the output was similar to the output below.
> I thought that this was correct, perhaps it is not??
> If I just leave AFPL GS as it is, I can display the passwd file with your
> test script.
>

I have just installed AFPL Ghostscript 7.03, and found that I had to
replace part of the file:

  gs_init.ps

with this code:

% If we want a "safer" system, disable some obvious ways to cause havoc.
SAFER not { (%END SAFER) .skipeof } if

.currentglobal true .setglobal
/SAFETY 2 dict
  dup /safe DELAYSAFER not put
  dup /tempfiles 10 dict put
readonly def
.setglobal

/.setsafe
  { //SAFETY /safe //true .forceput % overrides readonly
  } .bind executeonly odef

/file
 { //SAFETY /safe get {
     dup (r) eq
     2 index (%pipe*) .stringmatch not and
     3 index (%std*)  .stringmatch not and
     or or
       { file }
       { /invalidfileaccess //signalerror exec }
     ifelse
   } {
     file
   } ifelse
 } .bind executeonly odef


Here are the actual SCCS diffs of the file:

------- gs_init.ps -------
1567,1568c1567,1570
<      dup (r) eq 2 index (%pipe*) .stringmatch not and
<      2 index (%std*) .stringmatch or
---
>      dup (r) eq
>      2 index (%pipe*) .stringmatch not and
>      3 index (%std*)  .stringmatch not and
>      or or

The changes noted in the IFHP file:

  README.GhostScriptSecurityProblem

don't work for this version of Ghostscript.  There was also some some
traffic on this list about AFPL Ghostscript 7.0, but the changes to
gs_init.ps noted in that exchange also did not work.

I don't know what side effects my code (above) will cause--I'm not a
PostScript programmer.  But it does pass Patrick's diabolical "get the
root password" test and also prints my basic PostScript files.

Carl

Carl G. Riches
Software Engineer
Department of Mathematics
Box 354350                      voice:     206-543-5082 or 206-616-3636
University of Washington        fax:       206-543-0397
Seattle, WA  98195-4350         internet:  [EMAIL PROTECTED]

>
>   >
>   > Patrick
>   >
>   > > From [EMAIL PROTECTED] Sun Dec 23 19:03:32 2001
>   > > To: [EMAIL PROTECTED]
>   > > Subject: LPRng: AFPL Ghostscript 7.03 with suggested -dSAFER modification
>   > > Date: Mon, 24 Dec 2001 13:31:19 +1100
>   > > From: "C. L. McAvaney" <[EMAIL PROTECTED]>
>   > >
>   > > G'day,
>   > > I have put in the suggested modifications to gs_init.ps from the ifhp
>   > > README.GhostScriptSecurityProblem file and now when I want to view a prop
>   >er
>   > > Postscript file I get the following:
>   > >
>   > > gs -dSAFER UTILS/one.ps
>   > > AFPL Ghostscript 7.03 (2001-10-20)
>   > > Copyright (C) 2001 artofcode LLC, Benicia, CA.  All rights reserved.
>   > > This software comes with NO WARRANTY: see the file PUBLIC for details.
>   > > Error: /invalidfileaccess in -file-
>   > > Operand stack:
>   > >
>   > > Execution stack:
>   > >    %interp_exit   .runexec2   --nostringval--   --nostringval--   --nostr
>   >ingval--   2   %stopped_push   --nostringval--   --nostringval--   --nostrin
>   >gval--   false   1   %stopped_push   1   3   %oparray_pop   --nostringval--
>   >  --nostringval--
>   > > Dictionary stack:
>   > >    --dict:999/1123(ro)(G)--   --dict:0/20(G)--   --dict:67/200(L)--
>   > > Current allocation mode is local
>   > > Current file position is 0
>   > > AFPL Ghostscript 7.03: Unrecoverable error, exit code 1
>   > > 1
>   > > Unrecoverable error: invalidfileaccess in w
>   > > Operand stack:
>   > >     %stdout
>   > >
>   > > Does anybody else have a similar problem?
>   > >
>   > > Christopher
>   > >             ,,,
>   > >            (. .)
>   > > /-----.oOO--(_)--OOo.-------------------------------------------------\
>   > > |  Christopher McAvaney                       [EMAIL PROTECTED]   |
>   > > |  PhD Candidate                                 [EMAIL PROTECTED]   |
>   > > |                                               [EMAIL PROTECTED]   |
>   > > |  phone: +61+3+52272960                    [EMAIL PROTECTED]   |
>   > > |    fax: +61+3+52272028       http://www.cm.deakin.edu.au/~chrismc   |
>   > > \---------------------------------------------------------------------/
>   > >
>   > >
>   > > -------------------------------------------------------------------------
>   >----
>   > > YOU MUST BE A LIST MEMBER IN ORDER TO POST TO THE LPRNG MAILING LIST
>   > > The address you post from MUST be your subscription address
>   > >
>   > > If you need help, send email to [EMAIL PROTECTED] (or lprng-requests
>   > > or lprng-digest-requests) with the word 'help' in the body.  For the impa
>   >tient,
>   > > to subscribe to a list with name LIST,  send mail to [EMAIL PROTECTED]
>   > > with:                           | example:
>   > > subscribe LIST <mailaddr>       |  subscribe lprng-digest [EMAIL PROTECTED]
>   > > unsubscribe LIST <mailaddr>     |  unsubscribe lprng [EMAIL PROTECTED]
>   > >
>   > > If you have major problems,  send email to [EMAIL PROTECTED] with the w
>   >ord
>   > > LPRNGLIST in the SUBJECT line.
>   > > -------------------------------------------------------------------------
>   >----
>   > >
>   >
>   > ---------------------------------------------------------------------------
>   >--
>   > YOU MUST BE A LIST MEMBER IN ORDER TO POST TO THE LPRNG MAILING LIST
>   > The address you post from MUST be your subscription address
>   >
>   > If you need help, send email to [EMAIL PROTECTED] (or lprng-requests
>   > or lprng-digest-requests) with the word 'help' in the body.  For the impati
>   >ent,
>   > to subscribe to a list with name LIST,  send mail to [EMAIL PROTECTED]
>   > with:                           | example:
>   > subscribe LIST <mailaddr>       |  subscribe lprng-digest [EMAIL PROTECTED]
>   > unsubscribe LIST <mailaddr>     |  unsubscribe lprng [EMAIL PROTECTED]
>   >
>   > If you have major problems,  send email to [EMAIL PROTECTED] with the wor
>   >d
>   > LPRNGLIST in the SUBJECT line.
>   > ---------------------------------------------------------------------------
>   >--
>   >
>
> Christopher
>             ,,,
>            (. .)
> /-----.oOO--(_)--OOo.-------------------------------------------------\
> |  Christopher McAvaney                       [EMAIL PROTECTED]   |
> |  PhD Candidate                                 [EMAIL PROTECTED]   |
> |                                               [EMAIL PROTECTED]   |
> |  phone: +61+3+52272960                    [EMAIL PROTECTED]   |
> |    fax: +61+3+52272028       http://www.cm.deakin.edu.au/~chrismc   |
> \---------------------------------------------------------------------/
>
> -----------------------------------------------------------------------------
> YOU MUST BE A LIST MEMBER IN ORDER TO POST TO THE LPRNG MAILING LIST
> The address you post from MUST be your subscription address
>
> If you need help, send email to [EMAIL PROTECTED] (or lprng-requests
> or lprng-digest-requests) with the word 'help' in the body.  For the impatient,
> to subscribe to a list with name LIST,  send mail to [EMAIL PROTECTED]
> with:                           | example:
> subscribe LIST <mailaddr>       |  subscribe lprng-digest [EMAIL PROTECTED]
> unsubscribe LIST <mailaddr>     |  unsubscribe lprng [EMAIL PROTECTED]
>
> If you have major problems,  send email to [EMAIL PROTECTED] with the word
> LPRNGLIST in the SUBJECT line.
> -----------------------------------------------------------------------------


-----------------------------------------------------------------------------
YOU MUST BE A LIST MEMBER IN ORDER TO POST TO THE LPRNG MAILING LIST
The address you post from MUST be your subscription address

If you need help, send email to [EMAIL PROTECTED] (or lprng-requests
or lprng-digest-requests) with the word 'help' in the body.  For the impatient,
to subscribe to a list with name LIST,  send mail to [EMAIL PROTECTED]
with:                           | example:
subscribe LIST <mailaddr>       |  subscribe lprng-digest [EMAIL PROTECTED]
unsubscribe LIST <mailaddr>     |  unsubscribe lprng [EMAIL PROTECTED]

If you have major problems,  send email to [EMAIL PROTECTED] with the word
LPRNGLIST in the SUBJECT line.
-----------------------------------------------------------------------------

Reply via email to