GhostscriptɳÏäÈÆ¹ýºÅÁîÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-08-13

? ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10216£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ºÏÓÃÓÚ5b85ddd19a8420a1bd2d5529325be35d78e94234°æ±¾


·ì϶¸ÅÊö


GhostscriptÊÇÒ»Ì×½¨»ùÓÚAdobe¡¢PostScript¼°¿ÉÒÆÖ²ÎĵµÌåʽ£¨PDF£©µÄÒ³ÃæÃèÊö˵»°µÈ¶ø±àÒë³ÉµÄÃâ·ÑÈí¼þ ¡£


Ghostscript×÷ΪͼÏñ´¦ÖÃÌåʽת»»µÄµ×²ãÀûÓ㬷ì϶µ¼ÖÂËùÓÐÒýÓÃGhostscriptµÄÉÏÓÎÀûÓÃÊܵ½Ó°Ïì£¬Éæ¼°µ«²»ÏÞÓÚ£ºimagemagick¡¢libmagick¡¢graphicsmagick¡¢gimp¡¢python-matplotlib¡¢texlive-core¡¢texmacs¡¢latex2html¡¢latex2rtfµÈ ¡£


¸Ã·ì϶ԴÓÚ.buildfont1 Ö¸ÁîÔÚÖ´ÐеÄʱ³½Ã»ÓÐÕýÈ·±£»¤²Ö¿âÖеݲȫ״̬£¬µ¼ÖÂ-dSAFER°²È«É³Ïä״̬±»Èƹý ¡£¸Ã·ì϶Äܹ»Ö±½ÓÈÆ¹ý Ghostscript µÄ°²È«É³Ï䣬µ¼Ö¹¥»÷ÕßÄܹ»¶ÁÈ¡ËÁÒâÎļþ»òºÅÁîÖ´ÐÐ ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP ¡£


½¨¸´½¨Òé


1¡¢½¨Òé¸üе½5b85ddd19a8420a1bd2d5529325be35d78e94234Ö®ºóµÄ°æ±¾£¬»òÕßÖ±½Ó³ÁÐÂÀ­È¡master·ÖÖ§½øÐиüУ»


2¡¢redhat/debain µÈ¿¯Ðаæ¾ùÒѸüÐÂÉÏÓÎpackage£º


https://access.redhat.com/security/cve/cve-2019-10216
https://security-tracker.debian.org/tracker/CVE-2019-10216


»º½â´ëÊ©£º


ÈôÎÞ·¨¸üпÉÏȳ¢ÊÔ½ûÓÃʹÓÃgs½âÎöpsÎļþ£º


ʹÓÃImageMagick£¬½¨ÒéÅú¸ÄpolicyÎļþ:£¨Ä¬ÈϵØÎ»£º/etc/ImageMagick/policy.xml£©£¬ÔÚÖвÎÓëÒÔÏ£¨¼´½ûÓà PS¡¢EPS¡¢PDF¡¢XPS coders¡¢PCD£©£¬¾ßÌåÈçͼËùʾ£º

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


²Î¿¼Á´½Ó


https://www.openwall.com/lists/oss-security/2019/08/12/4