GhostScript -dSAFER¶à¸öɳÏäÈÆ¹ýÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-29

?Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-14811£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.3£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-14812£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.3£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-14813£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.3£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-14817£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.3£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


?Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Ghostscript commit f531552c99a04f003412f7a83d4661e927f88d40֮ǰ°æ±¾


?Îó²î¸ÅÊö


2019Äê8ÔÂ28ÈÕ£¬£¬£¬Artifex¹Ù·½ÔÚghostscriptµÄmaster·ÖÖ§ÉÏÌá½»Bug 701446: Avoid divide by zero in shading£¬£¬£¬ÐÞ¸´ÁË4¸ö-dSAFERɳÏäÈÆ¹ýÎó²î¡£¡£ ¡£¡£ ¡£¡£¡£¡£-dSAFERÊÇGhostscriptÓÃÓÚ±ÜÃâ²»Çå¾²PostScript²Ù×÷µÄÇ徲ɳÏä¡£¡£ ¡£¡£ ¡£¡£¡£¡£


GhostscriptÊÇÒ»Ì×»ùÓÚAdobe¡¢PostScript¼°¿ÉÒÆÖ²ÎĵµÃûÌã¨PDF£©µÈÒ³ÃæÐÎòÓïÑÔ¶ø±àÒë³ÉµÄÃâ·ÑͼÏñ´¦Öóͷ£Èí¼þ£¬£¬£¬±»ÆÕ±éÓ¦ÓÃÓÚͼƬ´¦Öóͷ£×é¼þ¡£¡£ ¡£¡£ ¡£¡£¡£¡£ÏÖÔÚÒѾ­´ÓLinux°æ±¾ÒÆÖ²µ½ÆäËû²Ù×÷ϵͳ£¬£¬£¬ÈçÆäËûUnix¡¢Mac OS X¡¢VMS¡¢Windows¡¢OS/2ºÍMac OS classic¡£¡£ ¡£¡£ ¡£¡£¡£¡£


´Ë´ÎÅû¶µÄ4¸öÎó²î»®·Ö±£´æÓÚ.pdf_hook_DSC_Creator£¨CVE-2019-14811£©¡¢.setuserparams2£¨CVE-2019-14812£©¡¢setsystemparams£¨CVE-2019-14813£©¼°.pdfexectoken£¨CVE-2019-14817£©¹¦Ð§ÖУ¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâ½á¹¹µÄpostscriptÎļþ»ñµÃ.forceputµÄ²Ù×÷ȨÏÞ£¬£¬£¬Èƹý-dSAFERµÄ·À»¤£¬£¬£¬Ö´ÐÐí§ÒâÏÂÁî¡£¡£ ¡£¡£ ¡£¡£¡£¡£Îó²îÓ°ÏìËùÓÐʹÓà GhostscriptÀ´´¦Öóͷ£PostScriptÄÚÈݵÄÓ¦Óᣡ£ ¡£¡£ ¡£¡£¡£¡£


?Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£ ¡£¡£ ¡£¡£¡£¡£


?ÐÞ¸´½¨Òé


Ä¿½ñ¹Ù·½ÔÝδÐû²¼ÐÞ¸´¸ÃÎó²îµÄrelease°æ±¾£¬£¬£¬Óû§¿ÉʹÓÃgitÏÂÁî¸üе½commit f531552c99a04f003412f7a83d4661e927f88d40Ö®ºóµÄ°æ±¾£º


CVE-2019-14811£¬£¬£¬CVE-2019-14812£¬£¬£¬CVE-2019-14813£º

http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=885444fcbe10dc42787ecb76686c8ee4dd33bf33


CVE-2019-14817£º

http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=cd1b1cacadac2479e291efe611979bdc1b3bdb19


»òÕßÖ±½ÓÀ­È¡master·ÖÖ§´úÂë¶Ô´ËÎó²îʵÏÖ·À»¤¡£¡£ ¡£¡£ ¡£¡£¡£¡£

http://git.ghostscript.com/?p=ghostpdl.git;a=summary


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


RedHat 7ºÍ8¿¯ÐаæÒѸüÐÂÐÞ¸´´ËÎó²î£¬£¬£¬ÇëÏà¹ØÓû§¾¡¿ì¾ÙÐÐÉý¼¶¡£¡£ ¡£¡£ ¡£¡£¡£¡£¹Ù·½ÒѲ»ÔÙά»¤Red Hat Enterprise Linux 5ºÍRed Hat Enterprise Linux 6°æ±¾£¬£¬£¬Ê¹ÓÃÕâÁ½¸ö°æ±¾µÄÓû§Ðè½ÓÄÉÔÝʱ»º½â²½·¥£¬£¬£¬¶Ô´ËÎó²î¾ÙÐзÀ»¤£º


https://access.redhat.com/security/cve/cve-2019-14811

https://access.redhat.com/security/cve/cve-2019-14812

https://access.redhat.com/security/cve/cve-2019-14813

https://access.redhat.com/security/cve/cve-2019-14817


ÔÝʱ»º½â²½·¥


ÈôÓû§Ôݲ»Àû±ãÉý¼¶ÖÁÐÞ¸´°æ±¾£¬£¬£¬¿Éͨ¹ýÒÔÏÂËùÁеÄÈýÖÖÒªÁìÀ´¾ÙÐзÀ»¤¡£¡£ ¡£¡£ ¡£¡£¡£¡£


1¡¢ImageMagickĬÈÏʹÓÃGhostscript×÷ΪÆÊÎöÆ÷´¦Öóͷ£PostScriptÄÚÈÝ£¬£¬£¬Òò´Ë£¬£¬£¬Óû§¿Éͨ¹ýÉèÖÃImageMagick×é¼þµÄPolicy.xmlÇå¾²Õ½ÂÔ£¬£¬£¬½ûÓÃghostscript¼°PS¡¢EPS¡¢PDF¡¢XPS±àÂëÆ÷À´ÊµÏÖ¶Ô´ËÎó²îµÄÓÐÓ÷À»¤¡£¡£ ¡£¡£ ¡£¡£¡£¡£


ImageMagickµÄpolicyÉèÖÃÎļþĬÈÏ·¾¶Îª/etc/ImageMagick/policy.xml£¬£¬£¬Ìí¼ÓÈçÏ´úÂëÖÁ<policymap>²¿·Ö£º


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


2¡¢Ghostscript´¦Öóͷ£ÎļþÔÚÌìÉúËõÂÔͼʱ¿ÉÄÜ´¥·¢¸ÃÀàÎó²î£¬£¬£¬¿Éͨ¹ýɾ³ý»òÕßÖØ

ÃüÃûÓÐÖ´ÐÐȨÏ޵ġ°/usr/bin/evince-thumbnailer¡±À´»º½â´ËÎó²î


3¡¢ä¯ÀÀPDF»òÕßPSÎļþʱ£¬£¬£¬¿ÉÔÚSELinuxɳÏäÖз­¿ª¿ÉÒÉÎļþ£¬£¬£¬ÀýÈçʹÓÃevince·­¿ªpdfÎļþ£¬£¬£¬¿ÉÒÔʹÓÃÈçÏÂÏÂÁ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


?²Î¿¼Á´½Ó


https://www.openwall.com/lists/oss-security/2019/08/28/2