Sabon rauni a cikin Ghostscript

Jerin raunin raunin baya tsayawa (1, 2, 3, 4, 5, 6) a cikin Fatalwa, saitin kayan aiki don sarrafawa, canzawa da samar da takardu a cikin PostScript da tsarin PDF. Kamar raunin da ya gabata sabuwar matsala (CVE-2019-10216) yana ba da damar, lokacin sarrafa takaddun da aka kera na musamman, don ƙetare yanayin keɓewar "-dSAFER" (ta hanyar yin amfani da ".buildfont1") da samun damar shiga abubuwan da ke cikin tsarin fayil, wanda za'a iya amfani da shi don tsara harin don aiwatar da lambar sabani. a cikin tsarin (misali, ta ƙara umarni zuwa ~ /.bashrc ko ~/.profile). Ana samun gyara kamar faci. Kuna iya bin diddigin samuwar sabuntawar fakiti a cikin rabawa akan waɗannan shafuka: Debian, Fedora, Ubuntu, SUSE/budeSUSE, RHEL, Arch, FreeBSD.

Bari mu tunatar da ku cewa raunin da ke cikin Ghostscript yana haifar da ƙarin haɗari, tunda ana amfani da wannan fakitin a cikin shahararrun aikace-aikace don sarrafa tsarin PostScript da PDF. Misali, ana kiran Ghostscript yayin ƙirƙirar babban hoto na tebur, firikwensin bayanan baya, da canza hoto. Don nasarar harin, a yawancin lokuta ya isa kawai zazzage fayil ɗin tare da amfani ko bincika kundin adireshi tare da shi a cikin Nautilus. Hakanan za'a iya amfani da rashin ƙarfi a cikin Ghostscript ta hanyar masu sarrafa hoto dangane da fakitin ImageMagick da GraphicsMagick ta hanyar wuce su fayil ɗin JPEG ko PNG mai ɗauke da lambar PostScript maimakon hoto (irin wannan fayil ɗin za'a sarrafa shi cikin Ghostscript, tunda nau'in MIME ana gane shi ta hanyar abun ciki, kuma ba tare da dogara ga tsawo ba).

source: budenet.ru

Add a comment