GhostscriptÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-08-23Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÎÞ£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
version<= 9.23£¨È«°æ±¾¡¢È«Æ½Ì¨£©¹Ù·½Î´³ö»º½â²½·¥£¬£¬£¬£¬×îа汾Êܵ½Ó°Ïì¡£¡£¡£
Îó²îµ¼ÖÂËùÓÐÒýÓÃGhostscriptµÄÉÏÓÎÓ¦ÓÃÊܵ½µ½Ó°Ïì¡£¡£¡£ÏÖÔÚArtifex Software£¬£¬£¬£¬ImageMagick£¬£¬£¬£¬Redhat£¬£¬£¬£¬UbuntuÒѾ˵Ã÷»áÊܵ½´ËÎó²îÓ°Ï죬£¬£¬£¬CoreOSÐû²¼²»ÊÜÓ°Ï죬£¬£¬£¬ÆäËûƽ̨ÔÝʱδ¶Ô´ËÎó²î¾ÙÐÐ˵Ã÷¡£¡£¡£
Îó²î¸ÅÊö
¿ËÈÕ£¬£¬£¬£¬Google ProjectZeroÇå¾²Ñо¿Ô±·¢Ã÷ºÜÊÇÊ¢ÐеÄÎĵµ´¦Öóͷ£¹¤¾ßGhostscript±£´æÇ徲ɳÏä±»ÈÆ¹ýµÄÎó²î¡£¡£¡£¹¥»÷Õß¿ÉÄÜͨ¹ýImageMagick¡¢Evince¡¢GIMP¡¢PDFÔĶÁÆ÷µÈÓ¦ÓÃÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬Ìá½»¶ñÒâ½á¹¹µÄͼƬÎļþ£¬£¬£¬£¬ÔÚÏà¹ØµÄЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£
GhostScript±»Ðí¶àͼƬ´¦Öóͷ£¿âËùʹÓ㬣¬£¬£¬ÈçImageMagick¡¢PythonPILµÈ£¬£¬£¬£¬Ä¬ÈÏÇéÐÎÏÂÕâЩ¿â»áƾ֤ͼƬµÄÄÚÈݽ«Æä·Ö·¢¸ø²î±ðµÄ´¦Öóͷ£ÒªÁ죬£¬£¬£¬ÆäÖоͰüÀ¨GhostScript¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ¹Ù·½ÉÐδÐû²¼²¹¶¡£¬£¬£¬£¬¿ÉÒÔʹÓÃÒÔÏÂÔÝʱ½â¾ö¼Æ»®£º
1. Ð¶ÔØ GhostScript£º
sudo apt-get removeghostscript£¨ÒÔUbuntu ϵͳΪÀý£©
2. ÔÚImageMagick policy.xmlÖнûÓÃPostScript¡¢EPS¡¢PDFÒÔ¼°XPS½âÂëÆ÷£¬£¬£¬£¬ÈçÏÂͼËùʾ£º
²Î¿¼Á´½Ó
http://seclists.org/oss-sec/2018/q3/142
https://bugs.chromium.org/p/project-zero/issues/detail?id=1640https://www.kb.cert.org/vuls/id/332928


¾©¹«Íø°²±¸11010802024551ºÅ