Chiwopsezo chatsopano mu Ghostscript

Mndandanda wa zofooka sizimayima (1, 2, 3, 4, 5, 6) mkati Chizindikiro, zida zosinthira, kusintha ndi kupanga zolemba mu PostScript ndi ma PDF. Monga zofooka zakale vuto latsopano (CVE-2019-10216) amalola, pokonza zikalata zopangidwa mwapadera, kudutsa njira yodzipatula ya "-dSAFER" (kudzera muzochita ndi ".buildfont1") ndikupeza zomwe zili mu fayilo, zomwe zingagwiritsidwe ntchito pokonzekera kuukira kuti apereke code yosagwirizana. m'dongosolo (mwachitsanzo, powonjezera malamulo ku ~ /.bashrc kapena ~/.profile). Kukonzekera kulipo ngati chigamba. Mutha kuyang'anira kupezeka kwa zosintha zamaphukusi pamagawidwe patsamba awa: Debian, Fedora, Ubuntu, SUSE/OpenSUSE, RHEL, Chipilala, FreeBSD.

Tikukumbutseni kuti kusatetezeka mu Ghostscript kumabweretsa chiwopsezo chowonjezereka, chifukwa phukusili limagwiritsidwa ntchito m'mapulogalamu ambiri otchuka pokonza ma PostScript ndi ma PDF. Mwachitsanzo, Ghostscript imatchedwa panthawi yopanga thumbnail pakompyuta, kulondolera deta yakumbuyo, ndi kusintha kwa zithunzi. Kuti muwukire bwino, nthawi zambiri ndikwanira kungotsitsa fayiloyo ndikugwiritsa ntchito kapena kuyang'ana chikwatu ndi Nautilus. Zowopsa mu Ghostscript zitha kugwiritsidwanso ntchito pogwiritsa ntchito ma processor azithunzi kutengera phukusi la ImageMagick ndi GraphicsMagick powapatsira fayilo ya JPEG kapena PNG yokhala ndi code ya PostScript m'malo mwa chithunzi (fayilo yotereyi idzasinthidwa mu Ghostscript, popeza mtundu wa MIME umadziwika ndi zokhutira, komanso popanda kudalira zowonjezera).

Source: opennet.ru

Kuwonjezera ndemanga