From 53f0cb4c54ac951697704cb87d24154ae08aecce Mon Sep 17 00:00:00 2001 From: Chris Liddell Date: Wed, 20 Feb 2019 09:54:28 +0000 Subject: [PATCH] Bug 700576: Make a transient proc executeonly (in DefineResource). This prevents access to .forceput Solution originally suggested by cbuissar@redhat.com. CVE: CVE-2019-3838 Upstream-Status: Backport [git://git.ghostscript.com/ghostpdl.git] Signed-off-by: Ovidiu Panait --- Resource/Init/gs_res.ps | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Resource/Init/gs_res.ps b/Resource/Init/gs_res.ps index 89c0ed6..a163541 100644 --- a/Resource/Init/gs_res.ps +++ b/Resource/Init/gs_res.ps @@ -426,7 +426,7 @@ status { % so we have to use .forceput here. currentdict /.Instances 2 index .forceput % Category dict is read-only } executeonly if - } + } executeonly { .LocalInstances dup //.emptydict eq { pop 3 dict localinstancedict Category 2 index put } -- 2.18.1