Kusagadzikana muGhostscript iyo inobvumira kuita kodhi kana uchivhura gwaro rePostScript

MuGhostscript, seti yezvishandiso zvekugadzirisa, kushandura uye kugadzira zvinyorwa muPostScript uye maPDF mafomati, kuzivikanwa kusagadzikana (CVE-2020-15900), izvo zvinogona kuita kuti mafaera agadziriswe uye mirairo isina musoro iitwe kana uchivhura zvinyorwa zvePostScript zvakagadzirirwa. Kushandisa isiri-standard PostScript operator mugwaro search inokutendera kuti ukonzerese kuwanda kwerudzi rweuint32_t paunenge uchiverenga saizi, nyora nzvimbo dzekurangarira kunze kwenzvimbo yakagoverwa uye kuwana mafaera muFS, ayo anogona kushandiswa kuronga kurwiswa kuti aite zvekupokana kodhi pane system (semuenzaniso, nekuwedzera mirairo ku ~/.bashrc kana ~/. profile).

Dambudziko rinokanganisa nyaya kubva 9.50 kusvika 9.52 ( kukanganisa present kubva kusunungurwa 9.28rc1, asi, maererano kupihwa vaongorori vakaona kusazvibata, kunoonekwa kubva muvhezheni 9.50).

Gadzirisa zvakarongwa mukuburitswa 9.52.1 (chigamba) Hotfix package yekuvandudza yakatoburitswa Debian, Ubuntu, suse. Mapakeji mukati RHEL matambudziko haabatike.

Ngatikuyeuchidzei kuti kusasimba muGhostscript kunoisa njodzi yakawedzera, sezvo pasuru iyi inoshandiswa mune zvakawanda zvakakurumbira zvikumbiro zvekugadzirisa PostScript uye mafomati ePDF. Semuenzaniso, Ghostscript inodaidzwa panguva yekugadzira zvidhori zvedesktop, yekumashure data indexing, uye kutendeuka kwemufananidzo. Kuti ubudirire kurwiswa, muzviitiko zvakawanda zvakakwana kungo dhawunirodha faira nekushandisa kana kutarisa dhairekitori nayo muNautilus. Kusagadzikana muGhostscript kunogona zvakare kushandiswa kuburikidza nemifananidzo processors zvichienderana ne ImageMagick uye GraphicsMagick mapakeji nekuvapa JPEG kana PNG faira rine PostScript code pachinzvimbo chemufananidzo (faira rakadaro richagadziriswa muGhostscript, sezvo mhando yeMIME ichizivikanwa ne zvemukati, uye pasina kuvimba nekuwedzera).

Source: opennet.ru

Voeg