{"id":91251,"date":"2020-08-10T13:42:19","date_gmt":"2020-08-10T11:42:19","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-ghostscript-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-postscript-dokumenta"},"modified":"2020-08-10T13:42:19","modified_gmt":"2020-08-10T11:42:19","slug":"uyazvimost-v-ghostscript-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-postscript-dokumenta","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-ghostscript-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-postscript-dokumenta","title":{"rendered":"Nj\u00eb vulnerabilitet n\u00eb Ghostscript, q\u00eb lejon ekzekutimin e kodit kur hapet nj\u00eb dokument PostScript","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb Ghostscript, nj\u00eb grup mjetesh p\u00ebr p\u00ebrpunimin, konvertimin dhe gjenerimin e dokumenteve n\u00eb formatet PostScript dhe PDF, <noindex><a rel=\"nofollow\" href=\"https:\/\/insomniasec.com\/blog\/ghostscript-cve-2020-15900\">u identifikua<\/a><\/noindex> vulneraibiliteti (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-15900\">CVE-2020-15900<\/a><\/noindex>), e cila mund t\u00eb \u00e7oj\u00eb n\u00eb ndryshimin e skedareve dhe ekzekutimin e komandeve t\u00eb \u00e7far\u00ebdo lloji kur hapen dokumente t\u00eb formatuara n\u00eb m\u00ebnyr\u00eb speciale n\u00eb formatin PostScript. P\u00ebrdorimi i nj\u00eb operatori jo standard PostScript n\u00eb dokument <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ArtifexSoftware\/ghostpdl\/blob\/master\/psi\/zstring.c#L109\">rsearch<\/a><\/noindex> lejon t\u00eb shkaktohet nj\u00eb mbushje e tipit uint32_t gjat\u00eb llogaritjes s\u00eb madh\u00ebsis\u00eb, t\u00eb shkruhet n\u00eb zona t\u00eb memories jasht\u00eb tamponit t\u00eb alokuar dhe t\u00eb qaset n\u00eb skedar\u00ebt n\u00eb FS, q\u00eb mund t\u00eb p\u00ebrdoret p\u00ebr t\u00eb organizuar nj\u00eb sulm p\u00ebr t\u00eb ekzekutuar kod t\u00eb \u00e7far\u00ebdo lloji n\u00eb sistem (p\u00ebr shembull, p\u00ebrmes shtimit t\u00eb komandeve n\u00eb ~\/.bashrc ose ~\/.profile).<\/p>\n<p>Problema preket <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ghostscript.com\/releases.html\">\u00e7do l\u00ebshim<\/a><\/noindex> nga 9.50 deri n\u00eb 9.52 (gabimi <noindex><a rel=\"nofollow\" href=\"https:\/\/git.ghostscript.com\/?p=ghostpdl.git;a=commitdiff;h=7ecbfda92b4c8dbf6f6c2bf8fc82020a29219eff\">\u00ebsht\u00eb prezent<\/a><\/noindex> duke filluar nga l\u00ebshimi 9.28rc1, por, sipas <noindex><a rel=\"nofollow\" href=\"https:\/\/insomniasec.com\/blog\/ghostscript-cve-2020-15900\">t\u00eb dh\u00ebnave<\/a><\/noindex> hulumtuesve q\u00eb identifikuan vulnerabilitetin, shfaqet q\u00eb nga versioni 9.50).<\/p>\n<p> Rregullimi \u00ebsht\u00eb propozuar n\u00eb l\u00ebshimin <noindex><a rel=\"nofollow\" href=\"https:\/\/git.ghostscript.com\/?p=ghostpdl.git;a=tag;h=6190b43f9d55027d0d88223b10868c6fd61a7da8\">9.52.1<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/git.ghostscript.com\/?p=ghostpdl.git;a=commitdiff;h=5d499272b95a6b890a1397e11d20937de000d31b\">patch<\/a><\/noindex>). P\u00ebrdit\u00ebsimet e paketave me rregullimin tashm\u00eb jan\u00eb l\u00ebshuar p\u00ebr <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-15900\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4445-1\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.opensuse.org\/opensuse-security-announce\/2020-08\/msg00004.html\">SUSE<\/a><\/noindex>. Paketat n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2020-15900\">RHEL<\/a><\/noindex> nuk jan\u00eb t\u00eb prekura nga problemi.<\/p>\n<p>Ri kujtojm\u00eb se vulnerabilitetet n\u00eb Ghostscript paraqesin rrezik t\u00eb rritur, pasi ky paket\u00eb p\u00ebrdoret n\u00eb shum\u00eb aplikacione t\u00eb njohura p\u00ebr p\u00ebrpunimin e formateve PostScript dhe PDF. P\u00ebr shembull, Ghostscript thirret gjat\u00eb krijimit t\u00eb miniaturave n\u00eb desktop, gjat\u00eb indeksimit n\u00eb sfond t\u00eb t\u00eb dh\u00ebnave dhe gjat\u00eb konvertimit t\u00eb imazheve. P\u00ebr nj\u00eb sulm t\u00eb suksessh\u00ebm, n\u00eb shum\u00eb raste mjafton thjesht t\u00eb ngarkohet nj\u00eb skedar me eksploit ose t\u00eb shikohet nj\u00eb katalog me t\u00eb n\u00eb Nautilus. Vulnerabilitetet n\u00eb Ghostscript gjithashtu mund t\u00eb shfryt\u00ebzohen p\u00ebrmes trajtuesve t\u00eb imazheve t\u00eb bazuar n\u00eb paketat ImageMagick dhe GraphicsMagick, duke kaluar n\u00eb to nj\u00eb skedar JPEG ose PNG, n\u00eb t\u00eb cilin p\u00ebrve\u00e7 imazhit ndodhet kodi PostScript (ky skedar do t\u00eb p\u00ebrpunoj\u00eb n\u00eb Ghostscript, pasi tipi MIME njihet sipas p\u00ebrmbajtjes dhe jo sipas zgjerimit).<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53480\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 Ghostscript, \u043d\u0430\u0431\u043e\u0440\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438, \u043f\u0440\u0435\u043e\u0431\u0440\u0430\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0430\u0445 PostScript \u0438 PDF, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-15900), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044e \u0444\u0430\u0439\u043b\u043e\u0432 \u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0443 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0445 \u043a\u043e\u043c\u0430\u043d\u0434 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0435 PostScript. \u0418\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 \u0432 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0435 \u043d\u0435\u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u043e\u0433\u043e PostScript-\u043e\u043f\u0435\u0440\u0430\u0442\u043e\u0440\u0430 rsearch \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0442\u0438\u043f\u0430 uint32_t \u043f\u0440\u0438 \u0432\u044b\u0447\u0438\u0441\u043b\u0435\u043d\u0438\u0438 \u0440\u0430\u0437\u043c\u0435\u0440\u0430, \u043f\u0435\u0440\u0435\u043f\u0438\u0441\u0430\u0442\u044c \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u043f\u0430\u043c\u044f\u0442\u0438 \u0432\u043d\u0435 \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u043d\u043e\u0433\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-91251","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 Ghostscript, \u043d\u0430\u0431\u043e\u0440\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438, \u043f\u0440\u0435\u043e\u0431\u0440\u0430\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0430\u0445 PostScript \u0438 PDF,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-ghostscript-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-postscript-dokumenta\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Ghostscript, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438 PostScript-\u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 Ghostscript, \u043d\u0430\u0431\u043e\u0440\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438, \u043f\u0440\u0435\u043e\u0431\u0440\u0430\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0430\u0445 PostScript \u0438 PDF,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-ghostscript-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-postscript-dokumenta\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-08-10T11:42:19+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-08-10T11:42:19+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabiliteti n\u00eb Ghostscript q\u00eb lejon ekzekutimin e kodit gjat\u00eb hapjes s\u00eb dokumentit PostScript | ProHoster","description":"N\u00eb Ghostscript, nj\u00eb grup mjetesh p\u00ebr p\u00ebrpunimin, konvertimin dhe gjenerimin e dokumenteve n\u00eb formatet PostScript dhe PDF,","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-ghostscript-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-postscript-dokumenta","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Ghostscript, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438 PostScript-\u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0430 | ProHoster","og:description":"\u0412 Ghostscript, \u043d\u0430\u0431\u043e\u0440\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438, \u043f\u0440\u0435\u043e\u0431\u0440\u0430\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0430\u0445 PostScript \u0438 PDF,","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-ghostscript-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-postscript-dokumenta","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-08-10T11:42:19+00:00","article:modified_time":"2020-08-10T11:42:19+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"91251","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:31:22","updated":"2022-10-13 08:06:29","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/91251","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=91251"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/91251\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=91251"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=91251"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=91251"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}