Vulnerability in Ghostscript exploited via ImageMagick

In Ghostscript, a toolkit for processing, converting, and generating documents in PostScript and PDF formats, a critical vulnerability (CVE-2021-3781) has been identified that allows arbitrary code execution when handling a specially crafted file. The issue was initially pointed out by Emil Lerner, who discussed the vulnerability on August 25 at the ZeroNights X conference in St. Petersburg (the presentation revealed how Emil used the vulnerability within bug bounty programs to earn rewards for demonstrating attacks on services like AirBNB, Dropbox, and Yandex.Real Estate).

On September 5, a working exploit was made publicly available, enabling attacks on systems with Ubuntu 20.04 by submitting a specially crafted document disguised as an image to a web script running on the server that uses the php-imagemagick package. Preliminary reports suggest that this exploit has been in circulation since March. It was initially claimed that it could target systems running GhostScript 9.50, but it was later discovered that the vulnerability is present in all subsequent versions of GhostScript, including the upcoming 9.55 release from Git.

A fix was proposed on September 8 and accepted into the GhostScript repository after review on September 9. In many distributions, the issue remains unaddressed (the status of update releases can be monitored on the pages for Debian, Ubuntu, Fedora, SUSE, RHEL, Arch Linux, FreeBSD, and NetBSD). The GhostScript release that resolves the vulnerability is expected to be published by the end of the month.

The problem is caused by the ability to bypass the isolation mode '-dSAFER' due to insufficient parameter checking on the PostScript device '%pipe%', which allowed arbitrary shell commands to be executed. For example, to execute the id utility in a document, it's sufficient to specify the line '(%pipe%/tmp/&id)(w)file' or '(%pipe%/tmp/;id)(r)file'.

It is important to note that vulnerabilities in Ghostscript pose a heightened risk, as this package is used in many popular applications for processing PostScript and PDF formats. For example, Ghostscript is called during the creation of thumbnails on the desktop, during background data indexing, and when converting images. In many cases, simply uploading an exploit file or browsing a directory containing it in a file manager that supports document thumbnail previews, such as Nautilus, is sufficient for a successful attack.

Vulnerabilities in Ghostscript can also be exploited through image handlers based on ImageMagick and GraphicsMagick packages by passing them a JPEG or PNG file where instead of an image, there is PostScript code (such a file will be processed in Ghostscript since the MIME type is recognized based on content, not relying on the extension).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster