GhostscriptɳÏäÈÆ¹ýÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-13

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10216£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚ5b85ddd19a8420a1bd2d5529325be35d78e94234°æ±¾


Îó²î¸ÅÊö


GhostscriptÊÇÒ»Ì×½¨»ùÓÚAdobe¡¢PostScript¼°¿ÉÒÆÖ²ÎĵµÃûÌã¨PDF£©µÄÒ³ÃæÐÎòÓïÑԵȶø±àÒë³ÉµÄÃâ·ÑÈí¼þ ¡£¡£¡£


Ghostscript×÷ΪͼÏñ´¦Öóͷ£ÃûÌÃת»»µÄµ×²ãÓ¦Ó㬣¬£¬Îó²îµ¼ÖÂËùÓÐÒýÓÃGhostscriptµÄÉÏÓÎÓ¦ÓÃÊܵ½Ó°Ï죬£¬£¬Éæ¼°µ«²»ÏÞÓÚ£ºimagemagick¡¢libmagick¡¢graphicsmagick¡¢gimp¡¢python-matplotlib¡¢texlive-core¡¢texmacs¡¢latex2html¡¢latex2rtfµÈ ¡£¡£¡£


¸ÃÎó²îÔ´ÓÚ.buildfont1 Ö¸ÁîÔÚÖ´ÐеÄʱ¼äûÓÐ׼ȷ± £»£»£» £»£»¤¿ÍÕ»ÖеÄÇ徲״̬£¬£¬£¬µ¼ÖÂ-dSAFERÇ徲ɳÏä״̬±»Èƹý ¡£¡£¡£¸ÃÎó²î¿ÉÒÔÖ±½ÓÈÆ¹ý Ghostscript µÄÇ徲ɳÏ䣬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒÔ¶ÁÈ¡í§ÒâÎļþ»òÏÂÁîÖ´ÐÐ ¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP ¡£¡£¡£


ÐÞ¸´½¨Òé


1¡¢½¨Òé¸üе½5b85ddd19a8420a1bd2d5529325be35d78e94234Ö®ºóµÄ°æ±¾£¬£¬£¬»òÕßÖ±½ÓÖØÐÂÀ­È¡master·ÖÖ§¾ÙÐиüР£»£»£» £»£»


2¡¢redhat/debain µÈ¿¯Ðаæ¾ùÒѸüÐÂÉÏÓÎpackage£º


https://access.redhat.com/security/cve/cve-2019-10216
https://security-tracker.debian.org/tracker/CVE-2019-10216


»º½â²½·¥£º


ÈôÎÞ·¨¸üпÉÏÈʵÑé½ûÓÃʹÓÃgsÆÊÎöpsÎļþ£º


ʹÓÃImageMagick£¬£¬£¬½¨ÒéÐÞ¸ÄpolicyÎļþ:£¨Ä¬ÈÏλÖãº/etc/ImageMagick/policy.xml£©£¬£¬£¬ÔÚÖмÓÈëÒÔÏ£¨¼´½ûÓà PS¡¢EPS¡¢PDF¡¢XPS coders¡¢PCD£©£¬£¬£¬ÏêϸÈçͼËùʾ£º

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


²Î¿¼Á´½Ó


https://www.openwall.com/lists/oss-security/2019/08/12/4