GhostscriptÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-08-23

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÎÞ£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


version<= 9.23£¨È«°æ±¾¡¢È«Æ½Ì¨£©¹Ù·½Î´³ö»º½â²½·¥£¬£¬£¬£¬£¬£¬×îа汾Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£


Îó²îµ¼ÖÂËùÓÐÒýÓÃGhostscriptµÄÉÏÓÎÓ¦ÓÃÊܵ½µ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚArtifex Software£¬£¬£¬£¬£¬£¬ImageMagick£¬£¬£¬£¬£¬£¬Redhat£¬£¬£¬£¬£¬£¬UbuntuÒѾ­ËµÃ÷»áÊܵ½´ËÎó²îÓ°Ï죬£¬£¬£¬£¬£¬CoreOSÐû²¼²»ÊÜÓ°Ï죬£¬£¬£¬£¬£¬ÆäËûƽ̨ÔÝʱδ¶Ô´ËÎó²î¾ÙÐÐ˵Ã÷¡£¡£¡£¡£¡£¡£¡£


Îó²î¸ÅÊö


¿ËÈÕ£¬£¬£¬£¬£¬£¬Google ProjectZeroÇå¾²Ñо¿Ô±·¢Ã÷ºÜÊÇÊ¢ÐеÄÎĵµ´¦Öóͷ£¹¤¾ßGhostscript±£´æÇ徲ɳÏä±»ÈÆ¹ýµÄÎó²î¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÄÜͨ¹ýImageMagick¡¢Evince¡¢GIMP¡¢PDFÔĶÁÆ÷µÈÓ¦ÓÃÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬Ìá½»¶ñÒâ½á¹¹µÄͼƬÎļþ£¬£¬£¬£¬£¬£¬ÔÚÏà¹ØµÄЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£


GhostScript±»Ðí¶àͼƬ´¦Öóͷ£¿âËùʹÓ㬣¬£¬£¬£¬£¬ÈçImageMagick¡¢PythonPILµÈ£¬£¬£¬£¬£¬£¬Ä¬ÈÏÇéÐÎÏÂÕâЩ¿â»áƾ֤ͼƬµÄÄÚÈݽ«Æä·Ö·¢¸ø²î±ðµÄ´¦Öóͷ£ÒªÁ죬£¬£¬£¬£¬£¬ÆäÖоͰüÀ¨GhostScript¡£¡£¡£¡£¡£¡£¡£


ÔÚGhostscriptÖÐÓÉÓÚÒÔÍùµÄÇå¾²ÊÂÎñ£¬£¬£¬£¬£¬£¬Õë¶ÔÇå¾²ÎÊÌâGS¹Ù·½½ÓÄÉÔöÌí²ÎÊý-dSAFERÀ´¿ªÆôÇ徲ɳÏ䣬£¬£¬£¬£¬£¬µ«¸ÃɳÏäÔÚ³ÌÐòÖ´ÐÐÀú³ÌÖÐÓÉLockSafetyParamsÕâ¸öÖµ¾ÙÐпØÖÆ£¬£¬£¬£¬£¬£¬´Ë´ÎGoogle Project ZeroÇå¾²Ñо¿Ô±·¢Ã÷ͨ¹ýrestore²Ù×÷»á½«¸ÃÖµÀÖ³ÉÁýÕÖ£¬£¬£¬£¬£¬£¬µ¼ÖÂÇ徲ɳÏä±»ÈÆ¹ý£¬£¬£¬£¬£¬£¬Òý·¢ÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ¹Ù·½ÉÐδÐû²¼²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓÃÒÔÏÂÔÝʱ½â¾ö¼Æ»®£º


1. Ð¶ÔØ GhostScript£º

sudo apt-get removeghostscript£¨ÒÔUbuntu ϵͳΪÀý£©


2. ÔÚImageMagick policy.xmlÖнûÓÃPostScript¡¢EPS¡¢PDFÒÔ¼°XPS½âÂëÆ÷£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



²Î¿¼Á´½Ó


http://seclists.org/oss-sec/2018/q3/142

https://bugs.chromium.org/p/project-zero/issues/detail?id=1640
https://www.kb.cert.org/vuls/id/332928