New vulnerability in Ghostscript

The series of vulnerabilities continues (1, 2, 3, 4, 5, 6) in Ghostscript, a set of tools for processing, converting, and generating documents in PostScript and PDF formats. Like previous vulnerabilities, a new issue (CVE-2019-10216) allows for bypassing the isolation mode '-dSAFER' (through manipulation with '.buildfont1') and gaining access to filesystem contents, which could be exploited to conduct an attack to execute arbitrary code on the system (for example, by adding commands to ~/ .bashrc or ~/ .profile). The fix is available as a patch. The release of package updates in distributions can be tracked on these pages: Debian, Alpine, Ubuntu, Arch, SUSE/openSUSE, ALT, FreeBSD.

It should be noted that vulnerabilities in Ghostscript pose a heightened risk, as this package is used in many popular applications for processing PostScript and PDF formats. For instance, Ghostscript is invoked during thumbnail creation on the desktop, during background data indexing, and when converting images. In many cases, a successful attack may only require uploading a file with an exploit or viewing a directory containing it in Nautilus. Vulnerabilities in Ghostscript can also be exploited via image handlers based on ImageMagick and GraphicsMagick by passing a JPEG or PNG file that contains PostScript code instead of an image (this file will be processed in Ghostscript since the MIME type is recognized by content rather than relying on the extension).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster