GhostscriptËÁÒâÎļþ¶Áд·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-10-11

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-17961£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Ghostscript version <= 9.26


·ì϶¸ÅÊö


GhostscriptÊÇAdobe PostScriptºÍPDFµÄÚ¹ÊÍ˵»°£¬ºÃ¶àͼƬ´¦Öÿâ¾ùÓÐÒýÓ㬳£¼ûµÄÓÐ ImageMagick¡¢Python-Matplotlib¡¢Latex2htmlµÈ ¡£


±¾´Î·¢Ïֵķì϶¿ÉʹGhostscript µÄ°²È«É³Ïä±»ÈÆ¹ý£¬¶ñÒâ¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâµÄͼƬÄÚÈÝ£¬¿ÉÔì³ÉËÁÒâÎļþ¶Áд ¡£Ê¹ÓÃGhostscriptµÄWebÀûÓôæÔÚ±»Ô¶³ÌºÅÁî¹¥»÷µÄ·çÏÕ ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·ì϶µ¼ÖÂËùÓÐÒýÓÃghostscriptµÄÉÏÓÎÀûÓÃÊܵ½Ó°Ïì ¡£ ³£¼ûÀûÓÃÈçÏ£º

Imagemagick¡¢libmagick¡¢graphicsmagick¡¢gimp¡¢python-matplotlib¡¢texlive-core¡¢texmacs¡¢latex2html¡¢latex2rtfµÈ


·ì϶ÑéÖ¤


EXP£ºhttps://www.exploit-db.com/exploits/45573/

¹Ù·½¶Ô.forceputµÄʹÓýéÉÜ£¬¿ÉÄÜÇ¿Ôì¸üÐÂdictÖеÄÖµ ¡£Õâ´ÎµÄ·ìÏ¶ÖØÒªÔ­ÒòÒ²¾ÍÊÇÔÚ´¥·¢ÃýÎóµÄʱ³½ÓÉÓÚ»ú¹Ø³ö.forceputÁô´æÔÚÕ»ÖУ¬¶øºó±»×¢²á³ÉºÅÁîforceput½ø¶ø¶Ôsystemdict½øÐÐÅú¸Ä ¡£×îÖÕ´ïµ½bypass saferÒÔ¼°¿ªÆôÎļþ¶ÁдȨÏ޵ȲÙ×÷ ¡£


Ubuntu 16.04 ±¾µØÊ¹ÓÃ×îаæ GhostScript 9.25 ²âÊÔ PoC£¬³É¹¦¶ÁÈ¡ /etc/passwd Îļþ£¬ÒÔ¼°Ïò ~/.bashrc дÈëºÅÁîºóÃÅ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ImageMagick 7.0.8-12 ²âÊÔ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½¨¸´½¨Òé


Ghostscript¹Ù·½ÒѸø³ö»º½â´ëÊ©£¬Çëʵʱ¸üУº
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=a54c9e61e7d
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=a6807394bd94
ÎÞ·¨¸üеĿÉͨ¹ýÅú¸Äpolicy.xml½ûÓÃPS, EPS, PDF and XPS coders£¨»áÔì³ÉÓйØÖ°Äܲ»³ÉʹÓã©
È磺Åú¸ÄImageMagickµÄpolicyÎļþ£¬Ä¬ÈϵØÎ»Îª/etc/ImageMagick-7/policy.xml
Ôö³¤ÈçÏÂÄÚÈÝ£º
<policymap>
<policydomain="coder" rights="none" pattern="PS" />
<policydomain="coder" rights="none" pattern="EPS" />
<policydomain="coder" rights="none" pattern="PDF" />
<policydomain="coder" rights="none" pattern="XPS" />
</policymap>

ÈôÊDz»±ØÒªÊ¹ÓÃGhostScript£¬¿ÉÐ¶ÔØ ¡£


²Î¿¼Á´½Ó


https://mailclark.ai/email/original/16819467/593541/mxzCj2eeqRd2DhZOU0Es1rJVQeg?from_name=Tavis%20Ormandy