GhostscriptɳÏäÈÆ¹ýÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-13

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10216 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚ5b85ddd19a8420a1bd2d5529325be35d78e94234°æ±¾


Îó²î¸ÅÊö


GhostscriptÊÇÒ»Ì×½¨»ùÓÚAdobe¡¢PostScript¼°¿ÉÒÆÖ²ÎĵµÃûÌã¨PDF£©µÄÒ³ÃæÐÎòÓïÑԵȶø±àÒë³ÉµÄÃâ·ÑÈí¼þ¡£


Ghostscript×÷ΪͼÏñ´¦Öóͷ£ÃûÌÃת»»µÄµ×²ãÓ¦Óà £¬Îó²îµ¼ÖÂËùÓÐÒýÓÃGhostscriptµÄÉÏÓÎÓ¦ÓÃÊܵ½Ó°Ïì £¬Éæ¼°µ«²»ÏÞÓÚ£ºimagemagick¡¢libmagick¡¢graphicsmagick¡¢gimp¡¢python-matplotlib¡¢texlive-core¡¢texmacs¡¢latex2html¡¢latex2rtfµÈ¡£


¸ÃÎó²îÔ´ÓÚ.buildfont1 Ö¸ÁîÔÚÖ´ÐеÄʱ¼äûÓÐ׼ȷ±£»¤¿ÍÕ»ÖеÄÇ徲״̬ £¬µ¼ÖÂ-dSAFERÇ徲ɳÏä״̬±»Èƹý¡£¸ÃÎó²î¿ÉÒÔÖ±½ÓÈÆ¹ý Ghostscript µÄÇ徲ɳÏä £¬µ¼Ö¹¥»÷Õß¿ÉÒÔ¶ÁÈ¡í§ÒâÎļþ»òÏÂÁîÖ´ÐС£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£


ÐÞ¸´½¨Òé


1¡¢½¨Òé¸üе½5b85ddd19a8420a1bd2d5529325be35d78e94234Ö®ºóµÄ°æ±¾ £¬»òÕßÖ±½ÓÖØÐÂÀ­È¡master·ÖÖ§¾ÙÐиüУ»


2¡¢redhat/debain µÈ¿¯Ðаæ¾ùÒѸüÐÂÉÏÓÎpackage£º


https://access.redhat.com/security/cve/cve-2019-10216
https://security-tracker.debian.org/tracker/CVE-2019-10216


»º½â²½·¥£º


ÈôÎÞ·¨¸üпÉÏÈʵÑé½ûÓÃʹÓÃgsÆÊÎöpsÎļþ£º


ʹÓÃImageMagick £¬½¨ÒéÐÞ¸ÄpolicyÎļþ:£¨Ä¬ÈÏλÖãº/etc/ImageMagick/policy.xml£© £¬ÔÚÖмÓÈëÒÔÏ£¨¼´½ûÓà PS¡¢EPS¡¢PDF¡¢XPS coders¡¢PCD£© £¬ÏêϸÈçͼËùʾ£º

 

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


²Î¿¼Á´½Ó


https://www.openwall.com/lists/oss-security/2019/08/12/4