{"id":91251,"date":"2020-08-10T13:42:19","date_gmt":"2020-08-10T11:42:19","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-ghostscript-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-postscript-dokumenta"},"modified":"2020-08-10T13:42:19","modified_gmt":"2020-08-10T11:42:19","slug":"uyazvimost-v-ghostscript-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-postscript-dokumenta","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-ghostscript-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-postscript-dokumenta","title":{"rendered":"Sicherheitsanf\u00e4lligkeit in Ghostscript, die die Ausf\u00fchrung von Code beim \u00d6ffnen eines PostScript-Dokuments erm\u00f6glicht","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In Ghostscript, einem Toolset zur Verarbeitung, Umwandlung und Erstellung von Dokumenten in den Formaten PostScript und PDF, <noindex><a rel=\"nofollow\" href=\"https:\/\/insomniasec.com\/blog\/ghostscript-cve-2020-15900\">entdeckt<\/a><\/noindex> Schwachstelle (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-15900\">CVE-2020-15900<\/a><\/noindex>), die dazu f\u00fchren kann, dass Dateien ge\u00e4ndert werden und beliebige Befehle ausgef\u00fchrt werden, wenn speziell gestaltete Dokumente im PostScript-Format ge\u00f6ffnet werden. Die Verwendung eines nicht standardm\u00e4\u00dfigen PostScript-Operators <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ArtifexSoftware\/ghostpdl\/blob\/master\/psi\/zstring.c#L109\">rsearch<\/a><\/noindex> f\u00fchrt zu einem \u00dcberlauf des Typs uint32_t bei der Berechnung der Gr\u00f6\u00dfe, \u00fcberschreibt Speicherbereiche au\u00dferhalb des zugewiesenen Puffers und erm\u00f6glicht den Zugriff auf Dateien im Dateisystem, was f\u00fcr die Durchf\u00fchrung eines Angriffs zur Ausf\u00fchrung beliebigen Codes im System genutzt werden kann (zum Beispiel durch Hinzuf\u00fcgen von Befehlen in ~\/ .bashrc oder ~\/ .profile).<\/p>\n<p>zu nutzen. Das Problem betrifft <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ghostscript.com\/releases.html\">Versionen<\/a><\/noindex> von 9.50 bis 9.52 (Fehler <noindex><a rel=\"nofollow\" href=\"https:\/\/git.ghostscript.com\/?p=ghostpdl.git;a=commitdiff;h=7ecbfda92b4c8dbf6f6c2bf8fc82020a29219eff\">ungef\u00e4hr<\/a><\/noindex> ab der Version 9.28rc1, jedoch, laut <noindex><a rel=\"nofollow\" href=\"https:\/\/insomniasec.com\/blog\/ghostscript-cve-2020-15900\">Angaben<\/a><\/noindex> den forschenden Entdeckern, tritt ab Version 9.50 auf).<\/p>\n<p> Eine Behebung wurde in der Version <noindex><a rel=\"nofollow\" href=\"https:\/\/git.ghostscript.com\/?p=ghostpdl.git;a=tag;h=6190b43f9d55027d0d88223b10868c6fd61a7da8\">9.52.1<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/git.ghostscript.com\/?p=ghostpdl.git;a=commitdiff;h=5d499272b95a6b890a1397e11d20937de000d31b\">Patch<\/a><\/noindex>). Paketupdates mit der Behebung wurden bereits f\u00fcr <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-15900\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4445-1\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.opensuse.org\/opensuse-security-announce\/2020-08\/msg00004.html\">SUSE<\/a><\/noindex>. Pakete in <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2020-15900\">RHEL<\/a><\/noindex> sind nicht betroffen.<\/p>\n<p>Wir erinnern daran, dass Schwachstellen in Ghostscript eine erh\u00f6hte Gefahr darstellen, da dieses Paket in vielen beliebten Anwendungen zur Verarbeitung von PostScript- und PDF-Formaten verwendet wird. Beispielsweise wird Ghostscript bei der Erstellung von Miniaturen auf dem Desktop, bei der Hintergrundindizierung von Daten und der Umwandlung von Bildern aufgerufen. F\u00fcr einen erfolgreichen Angriff reicht es in vielen F\u00e4llen aus, einfach eine Datei mit einem Exploit hochzuladen oder das Verzeichnis mit ihr in Nautilus zu durchsuchen. Schwachstellen in Ghostscript k\u00f6nnen auch \u00fcber Bildverarbeitungsprogramme, die auf den Paketen ImageMagick und GraphicsMagick basieren, ausgenutzt werden, indem ein JPEG- oder PNG-Datei \u00fcbergeben wird, in der sich anstelle eines Bildes Code in PostScript befindet (eine solche Datei wird in Ghostscript verarbeitet, da der MIME-Typ nach dem Inhalt erkannt wird und nicht auf die Erweiterung angewiesen ist).<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53480\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 Ghostscript, \u043d\u0430\u0431\u043e\u0440\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438, \u043f\u0440\u0435\u043e\u0431\u0440\u0430\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0430\u0445 PostScript \u0438 PDF, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-15900), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044e \u0444\u0430\u0439\u043b\u043e\u0432 \u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0443 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0445 \u043a\u043e\u043c\u0430\u043d\u0434 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0435 PostScript. \u0418\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 \u0432 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0435 \u043d\u0435\u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u043e\u0433\u043e PostScript-\u043e\u043f\u0435\u0440\u0430\u0442\u043e\u0440\u0430 rsearch \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0442\u0438\u043f\u0430 uint32_t \u043f\u0440\u0438 \u0432\u044b\u0447\u0438\u0441\u043b\u0435\u043d\u0438\u0438 \u0440\u0430\u0437\u043c\u0435\u0440\u0430, \u043f\u0435\u0440\u0435\u043f\u0438\u0441\u0430\u0442\u044c \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u043f\u0430\u043c\u044f\u0442\u0438 \u0432\u043d\u0435 \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u043d\u043e\u0433\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-91251","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 Ghostscript, \u043d\u0430\u0431\u043e\u0440\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438, \u043f\u0440\u0435\u043e\u0431\u0440\u0430\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0430\u0445 PostScript \u0438 PDF,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-ghostscript-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-postscript-dokumenta\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Ghostscript, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438 PostScript-\u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 Ghostscript, \u043d\u0430\u0431\u043e\u0440\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438, \u043f\u0440\u0435\u043e\u0431\u0440\u0430\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0430\u0445 PostScript \u0438 PDF,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-ghostscript-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-postscript-dokumenta\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-08-10T11:42:19+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-08-10T11:42:19+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Eine Schwachstelle in Ghostscript, die die Ausf\u00fchrung von Code beim \u00d6ffnen eines PostScript-Dokuments erm\u00f6glicht | ProHoster","description":"In Ghostscript, einem Toolset zur Verarbeitung, Umwandlung und Erstellung von Dokumenten in den Formaten PostScript und PDF,","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-ghostscript-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-postscript-dokumenta","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Ghostscript, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438 PostScript-\u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0430 | ProHoster","og:description":"\u0412 Ghostscript, \u043d\u0430\u0431\u043e\u0440\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438, \u043f\u0440\u0435\u043e\u0431\u0440\u0430\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0430\u0445 PostScript \u0438 PDF,","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-ghostscript-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-postscript-dokumenta","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-08-10T11:42:19+00:00","article:modified_time":"2020-08-10T11:42:19+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"91251","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:31:22","updated":"2022-10-13 08:06:29","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/91251","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=91251"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/91251\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=91251"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=91251"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=91251"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}