GhostscriptºÅÁîÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-08-23

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


version<= 9.23£¨È«°æ±¾¡¢È«Æ½Ì¨£©¹Ù·½Î´³ö»º½â´ëÊ©£¬×îа汾Êܵ½Ó°Ïì¡£


·ì϶µ¼ÖÂËùÓÐÒýÓÃGhostscriptµÄÉÏÓÎÀûÓÃÊܵ½µ½Ó°Ï졣ĿǰArtifex Software£¬ImageMagick£¬Redhat£¬UbuntuÒѾ­×¢Ã÷»áÊܵ½´Ë·ì϶ӰÏ죬CoreOS°ä·¢²»ÊÜÓ°Ï죬ÆäËûƽ̨ÁÙʱδ¶Ô´Ë·ì϶½øÐÐ×¢Ã÷¡£


·ì϶¸ÅÊö


½üÈÕ£¬Google ProjectZero°²È«×êÑÐÔ±·¢ÏÖ¼«¶ÈÊ¢ÐеÄÎĵµ´¦Öù¤¾ßGhostscript´æÔÚ°²È«É³Ïä±»ÈÆ¹ýµÄ·ì϶¡£¹¥»÷Õß¿ÉÄÜͨ¹ýImageMagick¡¢Evince¡¢GIMP¡¢PDFÔĶÁÆ÷µÅצÓÃÀ´ÀûÓô˷ì϶£¬Ìá·´Ä¿Òâ»ú¹ØµÄͼƬÎļþ£¬ÔÚÓйصķþÎñÆ÷ÉÏÖ´ÐÐËÁÒâºÅÁî¡£


GhostScript±»ºÜ¶àͼƬ´¦ÖÿâËùʹÓã¬ÈçImageMagick¡¢PythonPILµÈ£¬Ä¬ÈÏÇé¿öÏÂÕâЩ¿â»áƾ¾ÝͼƬµÄÄÚÈݽ«Æä·Ö·¢¸ø·ÖÆçµÄ´¦Öò½Ö裬ÆäÖоÍÔ̺¬GhostScript¡£


ÔÚGhostscriptÖÐÓÉÓÚÒÔÍùµÄ°²È«ÊÂÎñ£¬Õë¶Ô°²È«ÎÊÌâGS¹Ù·½Ñ¡È¡Ôö³¤²ÎÊý-dSAFERÀ´¿ªÆô°²È«É³Ï䣬µ«¸ÃɳÏäÔÚ·¨Ê½Ö´Ðйý³ÌÖÐÓÉLockSafetyParamsÕâ¸öÖµ½øÐнÚÔ죬Õâ´ÎGoogle Project Zero°²È«×êÑÐÔ±·¢ÏÖͨ¹ýrestore²Ù×÷»á½«¸ÃÖµ³É¹¦¸²¸Ç£¬µ¼Ö°²È«É³Ïä±»ÈÆ¹ý£¬Òý·¢ºÅÁîÖ´Ðзì϶¡£


½¨¸´½¨Òé


Ŀǰ¹Ù·½ÉÐδ°ä²¼²¹¶¡£¬Äܹ»Ê¹ÓÃÒÔÏÂһʱ½â¾ö¹æ»®£º


1. Ð¶ÔØ GhostScript£º

sudo apt-get removeghostscript£¨ÒÔUbuntu ϵͳΪÀý£©


2. ÔÚImageMagick policy.xmlÖнûÓÃPostScript¡¢EPS¡¢PDFÒÔ¼°XPS½âÂëÆ÷£¬ÈçÏÂͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



²Î¿¼Á´½Ó


http://seclists.org/oss-sec/2018/q3/142

https://bugs.chromium.org/p/project-zero/issues/detail?id=1640
https://www.kb.cert.org/vuls/id/332928