e97353cf79
pstopnm called the ghostscript interpreter on potentially untrusted PostScript without specifying the -dSAFER option. Not running under -dSAFER allows PostScript code to do file IO and to open pipes to arbitrary external programs, including /bin/sh. Originally reported by Max Vozeler/Debian Linux; ok brad@ |
||
---|---|---|
.. | ||
files | ||
patches | ||
pkg | ||
distinfo | ||
Makefile |