GhostscriptɳÏäÈÆ¹ýºÅÁîÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-08-13

? ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10216£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ºÏÓÃÓÚ5b85ddd19a8420a1bd2d5529325be35d78e94234°æ±¾


·ì϶¸ÅÊö


GhostscriptÊÇÒ»Ì×½¨»ùÓÚAdobe¡¢PostScript¼°¿ÉÒÆÖ²ÎĵµÌåʽ£¨PDF£©µÄÒ³ÃæÃèÊö˵»°µÈ¶ø±àÒë³ÉµÄÃâ·ÑÈí¼þ¡£¡£ ¡£¡£¡£¡£¡£¡£


Ghostscript×÷ΪͼÏñ´¦ÖÃÌåʽת»»µÄµ×²ãÀûÓ㬣¬£¬£¬£¬£¬£¬£¬·ì϶µ¼ÖÂËùÓÐÒýÓÃGhostscriptµÄÉÏÓÎÀûÓÃÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬£¬Éæ¼°µ«²»ÏÞÓÚ£ºimagemagick¡¢libmagick¡¢graphicsmagick¡¢gimp¡¢python-matplotlib¡¢texlive-core¡¢texmacs¡¢latex2html¡¢latex2rtfµÈ¡£¡£ ¡£¡£¡£¡£¡£¡£


¸Ã·ì϶ԴÓÚ.buildfont1 Ö¸ÁîÔÚÖ´ÐеÄʱ³½Ã»ÓÐÕýÈ·±£»£»£»£»£»¤²Ö¿âÖеݲȫ״̬£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ-dSAFER°²È«É³Ïä״̬±»Èƹý¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã·ì϶Äܹ»Ö±½ÓÈÆ¹ý Ghostscript µÄ°²È«É³Ï䣬£¬£¬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»¶ÁÈ¡ËÁÒâÎļþ»òºÅÁîÖ´ÐС£¡£ ¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£ ¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


1¡¢½¨Òé¸üе½5b85ddd19a8420a1bd2d5529325be35d78e94234Ö®ºóµÄ°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬»òÕßÖ±½Ó³ÁÐÂÀ­È¡master·ÖÖ§½øÐиüУ»£»£»£»£»


2¡¢redhat/debain µÈ¿¯Ðаæ¾ùÒѸüÐÂÉÏÓÎpackage£º


https://access.redhat.com/security/cve/cve-2019-10216
https://security-tracker.debian.org/tracker/CVE-2019-10216


»º½â´ëÊ©£º


ÈôÎÞ·¨¸üпÉÏȳ¢ÊÔ½ûÓÃʹÓÃgs½âÎöpsÎļþ£º


ʹÓÃImageMagick£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÅú¸ÄpolicyÎļþ:£¨Ä¬ÈϵØÎ»£º/etc/ImageMagick/policy.xml£©£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÖвÎÓëÒÔÏ£¨¼´½ûÓà PS¡¢EPS¡¢PDF¡¢XPS coders¡¢PCD£©£¬£¬£¬£¬£¬£¬£¬£¬¾ßÌåÈçͼËùʾ£º

 

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


²Î¿¼Á´½Ó


https://www.openwall.com/lists/oss-security/2019/08/12/4