GhostscriptɳÏäÈÆ¹ýÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-13

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10216 £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚ5b85ddd19a8420a1bd2d5529325be35d78e94234°æ±¾


Îó²î¸ÅÊö


GhostscriptÊÇÒ»Ì×½¨»ùÓÚAdobe¡¢PostScript¼°¿ÉÒÆÖ²ÎĵµÃûÌã¨PDF£©µÄÒ³ÃæÐÎòÓïÑԵȶø±àÒë³ÉµÄÃâ·ÑÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£


Ghostscript×÷ΪͼÏñ´¦Öóͷ£ÃûÌÃת»»µÄµ×²ãÓ¦Óà £¬£¬£¬£¬Îó²îµ¼ÖÂËùÓÐÒýÓÃGhostscriptµÄÉÏÓÎÓ¦ÓÃÊܵ½Ó°Ïì £¬£¬£¬£¬Éæ¼°µ«²»ÏÞÓÚ£ºimagemagick¡¢libmagick¡¢graphicsmagick¡¢gimp¡¢python-matplotlib¡¢texlive-core¡¢texmacs¡¢latex2html¡¢latex2rtfµÈ¡£¡£¡£¡£¡£¡£¡£¡£


¸ÃÎó²îÔ´ÓÚ.buildfont1 Ö¸ÁîÔÚÖ´ÐеÄʱ¼äûÓÐ׼ȷ±£»£»£»£»£»£»£»¤¿ÍÕ»ÖеÄÇ徲״̬ £¬£¬£¬£¬µ¼ÖÂ-dSAFERÇ徲ɳÏä״̬±»Èƹý¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÒÔÖ±½ÓÈÆ¹ý Ghostscript µÄÇ徲ɳÏä £¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒÔ¶ÁÈ¡í§ÒâÎļþ»òÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


1¡¢½¨Òé¸üе½5b85ddd19a8420a1bd2d5529325be35d78e94234Ö®ºóµÄ°æ±¾ £¬£¬£¬£¬»òÕßÖ±½ÓÖØÐÂÀ­È¡master·ÖÖ§¾ÙÐиüУ»£»£»£»£»£»£»


2¡¢redhat/debain µÈ¿¯Ðаæ¾ùÒѸüÐÂÉÏÓÎpackage£º


https://access.redhat.com/security/cve/cve-2019-10216
https://security-tracker.debian.org/tracker/CVE-2019-10216


»º½â²½·¥£º


ÈôÎÞ·¨¸üпÉÏÈʵÑé½ûÓÃʹÓÃgsÆÊÎöpsÎļþ£º


ʹÓÃImageMagick £¬£¬£¬£¬½¨ÒéÐÞ¸ÄpolicyÎļþ:£¨Ä¬ÈÏλÖãº/etc/ImageMagick/policy.xml£© £¬£¬£¬£¬ÔÚÖмÓÈëÒÔÏ£¨¼´½ûÓà PS¡¢EPS¡¢PDF¡¢XPS coders¡¢PCD£© £¬£¬£¬£¬ÏêϸÈçͼËùʾ£º

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


²Î¿¼Á´½Ó


https://www.openwall.com/lists/oss-security/2019/08/12/4