GhostscriptɳÏäÈÆ¹ýÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-13

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10216£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚ5b85ddd19a8420a1bd2d5529325be35d78e94234°æ±¾


Îó²î¸ÅÊö


GhostscriptÊÇÒ»Ì×½¨»ùÓÚAdobe¡¢PostScript¼°¿ÉÒÆÖ²ÎĵµÃûÌã¨PDF£©µÄÒ³ÃæÐÎòÓïÑԵȶø±àÒë³ÉµÄÃâ·ÑÈí¼þ¡£


Ghostscript×÷ΪͼÏñ´¦Öóͷ£ÃûÌÃת»»µÄµ×²ãÓ¦Óã¬Îó²îµ¼ÖÂËùÓÐÒýÓÃGhostscriptµÄÉÏÓÎÓ¦ÓÃÊܵ½Ó°Ïì£¬Éæ¼°µ«²»ÏÞÓÚ£ºimagemagick¡¢libmagick¡¢graphicsmagick¡¢gimp¡¢python-matplotlib¡¢texlive-core¡¢texmacs¡¢latex2html¡¢latex2rtfµÈ¡£


¸ÃÎó²îÔ´ÓÚ.buildfont1 Ö¸ÁîÔÚÖ´ÐеÄʱ¼äûÓÐ׼ȷ±£»¤¿ÍÕ»ÖеÄÇ徲״̬£¬µ¼ÖÂ-dSAFERÇ徲ɳÏä״̬±»Èƹý¡£¸ÃÎó²î¿ÉÒÔÖ±½ÓÈÆ¹ý Ghostscript µÄÇ徲ɳÏ䣬µ¼Ö¹¥»÷Õß¿ÉÒÔ¶ÁÈ¡í§ÒâÎļþ»òÏÂÁîÖ´ÐС£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£


ÐÞ¸´½¨Òé


1¡¢½¨Òé¸üе½5b85ddd19a8420a1bd2d5529325be35d78e94234Ö®ºóµÄ°æ±¾£¬»òÕßÖ±½ÓÖØÐÂÀ­È¡master·ÖÖ§¾ÙÐиüУ»


2¡¢redhat/debain µÈ¿¯Ðаæ¾ùÒѸüÐÂÉÏÓÎpackage£º


https://access.redhat.com/security/cve/cve-2019-10216
https://security-tracker.debian.org/tracker/CVE-2019-10216


»º½â²½·¥£º


ÈôÎÞ·¨¸üпÉÏÈʵÑé½ûÓÃʹÓÃgsÆÊÎöpsÎļþ£º


ʹÓÃImageMagick£¬½¨ÒéÐÞ¸ÄpolicyÎļþ:£¨Ä¬ÈÏλÖãº/etc/ImageMagick/policy.xml£©£¬ÔÚÖмÓÈëÒÔÏ£¨¼´½ûÓà PS¡¢EPS¡¢PDF¡¢XPS coders¡¢PCD£©£¬ÏêϸÈçͼËùʾ£º

 

Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


²Î¿¼Á´½Ó


https://www.openwall.com/lists/oss-security/2019/08/12/4