GhostscriptɳÏäÈÆ¹ýÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-13

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-10216£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚ5b85ddd19a8420a1bd2d5529325be35d78e94234°æ±¾


Îó²î¸ÅÊö


GhostscriptÊÇÒ»Ì×½¨»ùÓÚAdobe¡¢PostScript¼°¿ÉÒÆÖ²ÎĵµÃûÌã¨PDF£©µÄÒ³ÃæÐÎòÓïÑԵȶø±àÒë³ÉµÄÃâ·ÑÈí¼þ¡£¡£¡£¡£¡£¡£¡£


Ghostscript×÷ΪͼÏñ´¦Öóͷ£ÃûÌÃת»»µÄµ×²ãÓ¦Ó㬣¬£¬£¬£¬£¬Îó²îµ¼ÖÂËùÓÐÒýÓÃGhostscriptµÄÉÏÓÎÓ¦ÓÃÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬Éæ¼°µ«²»ÏÞÓÚ£ºimagemagick¡¢libmagick¡¢graphicsmagick¡¢gimp¡¢python-matplotlib¡¢texlive-core¡¢texmacs¡¢latex2html¡¢latex2rtfµÈ¡£¡£¡£¡£¡£¡£¡£


¸ÃÎó²îÔ´ÓÚ.buildfont1 Ö¸ÁîÔÚÖ´ÐеÄʱ¼äûÓÐ׼ȷ±£»£»£»£»£»£»¤¿ÍÕ»ÖеÄÇ徲״̬£¬£¬£¬£¬£¬£¬µ¼ÖÂ-dSAFERÇ徲ɳÏä״̬±»Èƹý¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÒÔÖ±½ÓÈÆ¹ý Ghostscript µÄÇ徲ɳÏ䣬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒÔ¶ÁÈ¡í§ÒâÎļþ»òÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


1¡¢½¨Òé¸üе½5b85ddd19a8420a1bd2d5529325be35d78e94234Ö®ºóµÄ°æ±¾£¬£¬£¬£¬£¬£¬»òÕßÖ±½ÓÖØÐÂÀ­È¡master·ÖÖ§¾ÙÐиüУ»£»£»£»£»£»


2¡¢redhat/debain µÈ¿¯Ðаæ¾ùÒѸüÐÂÉÏÓÎpackage£º


https://access.redhat.com/security/cve/cve-2019-10216
https://security-tracker.debian.org/tracker/CVE-2019-10216


»º½â²½·¥£º


ÈôÎÞ·¨¸üпÉÏÈʵÑé½ûÓÃʹÓÃgsÆÊÎöpsÎļþ£º


ʹÓÃImageMagick£¬£¬£¬£¬£¬£¬½¨ÒéÐÞ¸ÄpolicyÎļþ:£¨Ä¬ÈÏλÖãº/etc/ImageMagick/policy.xml£©£¬£¬£¬£¬£¬£¬ÔÚÖмÓÈëÒÔÏ£¨¼´½ûÓà PS¡¢EPS¡¢PDF¡¢XPS coders¡¢PCD£©£¬£¬£¬£¬£¬£¬ÏêϸÈçͼËùʾ£º

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


²Î¿¼Á´½Ó


https://www.openwall.com/lists/oss-security/2019/08/12/4