GhostScript -dSAFER¶à¸öɳÏäÈÆ¹ý·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-08-29?·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-14811£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.3£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-14812£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.3£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-14813£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.3£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-14817£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.3£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
?Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
Ghostscript commit f531552c99a04f003412f7a83d4661e927f88d40֮ǰ°æ±¾
?·ì϶¸ÅÊö
2019Äê8ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬£¬Artifex¹Ù·½ÔÚghostscriptµÄmaster·ÖÖ§ÉÏÌá½»Bug 701446: Avoid divide by zero in shading£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁË4¸ö-dSAFERɳÏäÈÆ¹ý·ì϶¡£¡£¡£¡£¡£¡£¡£¡£-dSAFERÊÇGhostscriptÓÃÓÚÔ¤·À²»°²È«PostScript²Ù×÷µÄ°²È«É³Ïä¡£¡£¡£¡£¡£¡£¡£¡£
GhostscriptÊÇÒ»Ì×»ùÓÚAdobe¡¢PostScript¼°¿ÉÒÆÖ²ÎĵµÌåʽ£¨PDF£©µÈÒ³ÃæÃèÊö˵»°¶ø±àÒë³ÉµÄÃâ·ÑͼÏñ´¦ÖÃÈí¼þ£¬£¬£¬£¬£¬£¬£¬±»¿í·ºÀûÓÃÓÚͼƬ´¦ÖÃ×é¼þ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°ÒѾ´ÓLinux°æ±¾ÒÆÖ²µ½ÆäËû²Ù×÷ϵͳ£¬£¬£¬£¬£¬£¬£¬ÈçÆäËûUnix¡¢Mac OS X¡¢VMS¡¢Windows¡¢OS/2ºÍMac OS classic¡£¡£¡£¡£¡£¡£¡£¡£
Õâ´ÎÅû¶µÄ4¸ö·ì϶±ðÀë´æÔÚÓÚ.pdf_hook_DSC_Creator£¨CVE-2019-14811£©¡¢.setuserparams2£¨CVE-2019-14812£©¡¢setsystemparams£¨CVE-2019-14813£©¼°.pdfexectoken£¨CVE-2019-14817£©Ö°ÄÜÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâ»ú¹ØµÄpostscriptÎļþ»ñµÃ.forceputµÄ²Ù×÷ȨÏÞ£¬£¬£¬£¬£¬£¬£¬Èƹý-dSAFERµÄ·À»¤£¬£¬£¬£¬£¬£¬£¬Ö´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£·ì϶ӰÏìËùÓÐʹÓà GhostscriptÀ´´¦ÖÃPostScriptÄÚÈݵÄÀûÓᣡ£¡£¡£¡£¡£¡£¡£
?·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£
?½¨¸´½¨Òé
µ±Ç°¹Ù·½ÔÝδ°ä²¼½¨¸´¸Ã·ì϶µÄrelease°æ±¾£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉʹÓÃgitºÅÁî¸üе½commit f531552c99a04f003412f7a83d4661e927f88d40Ö®ºóµÄ°æ±¾£º
CVE-2019-14811£¬£¬£¬£¬£¬£¬£¬CVE-2019-14812£¬£¬£¬£¬£¬£¬£¬CVE-2019-14813£º
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=885444fcbe10dc42787ecb76686c8ee4dd33bf33
CVE-2019-14817£º
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=cd1b1cacadac2479e291efe611979bdc1b3bdb19
»òÕßÖ±½ÓÀÈ¡master·ÖÖ§´úÂë¶Ô´Ë·ì϶ʵÏÖ·À»¤¡£¡£¡£¡£¡£¡£¡£¡£
http://git.ghostscript.com/?p=ghostpdl.git;a=summary
RedHat 7ºÍ8¿¯ÐаæÒѸüн¨¸´´Ë·ì϶£¬£¬£¬£¬£¬£¬£¬ÇëÓйØÓû§¾¡¿ì½øÐÐÉý¼¶¡£¡£¡£¡£¡£¡£¡£¡£¹Ù·½ÒѲ»ÔÙÊØ»¤Red Hat Enterprise Linux 5ºÍRed Hat Enterprise Linux 6°æ±¾£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÕâÁ½¸ö°æ±¾µÄÓû§Ðè²Éȡһʱ»º½â´ëÊ©£¬£¬£¬£¬£¬£¬£¬¶Ô´Ë·ì϶½øÐзÀ»¤£º
https://access.redhat.com/security/cve/cve-2019-14811
https://access.redhat.com/security/cve/cve-2019-14812
https://access.redhat.com/security/cve/cve-2019-14813
https://access.redhat.com/security/cve/cve-2019-14817
һʱ»º½â´ëÊ©
ÈôÓû§Ôݲ»·½±ãÉý¼¶ÖÁ½¨¸´°æ±¾£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ýÒÔÏÂËùÁеÄÈýÖÖ²½ÖèÀ´½øÐзÀ»¤¡£¡£¡£¡£¡£¡£¡£¡£
1¡¢ImageMagickĬÈÏʹÓÃGhostscript×÷Ϊ½âÎöÆ÷´¦ÖÃPostScriptÄÚÈÝ£¬£¬£¬£¬£¬£¬£¬Òò¶ø£¬£¬£¬£¬£¬£¬£¬Óû§¿Éͨ¹ýÅäÖÃImageMagick×é¼þµÄPolicy.xml°²È«Õ½Êõ£¬£¬£¬£¬£¬£¬£¬½ûÓÃghostscript¼°PS¡¢EPS¡¢PDF¡¢XPS±àÂëÆ÷À´ÊµÏÖ¶Ô´Ë·ì϶µÄÓÐЧ·À»¤¡£¡£¡£¡£¡£¡£¡£¡£
ImageMagickµÄpolicyÅäÖÃÎļþĬÈÏõ辶Ϊ/etc/ImageMagick/policy.xml£¬£¬£¬£¬£¬£¬£¬Ôö³¤ÈçÏ´úÂëÖÁ<policymap>²¿ÃÅ£º
2¡¢Ghostscript´¦ÖÃÎļþÔÚÌìÉúËõÂÔͼʱ¿ÉÄÜ´¥·¢¸ÃÀà·ì϶£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ýɾ³ý»òÕß³Á
¶¨ÃûÓÐÖ´ÐÐȨÏ޵ġ°/usr/bin/evince-thumbnailer¡±À´»º½â´Ë·ì϶
3¡¢ä¯ÀÀPDF»òÕßPSÎļþʱ£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚSELinuxɳÏäÖдò¿ª¿ÉÒÉÎļþ£¬£¬£¬£¬£¬£¬£¬ÀýÈçʹÓÃevince´ò¿ªpdfÎļþ£¬£¬£¬£¬£¬£¬£¬Äܹ»Ê¹ÓÃÈçϺÅÁ
?²Î¿¼Á´½Ó
https://www.openwall.com/lists/oss-security/2019/08/28/2


¾©¹«Íø°²±¸11010802024551ºÅ