Bofokoli bo latelang ba 4 ho Ghostscript

Kamora libeke tse peli ho batla taba e mahlonoko e fetileng ka Kaholimo tsebahatsoa 4 tse ling tse tšoanang vulnerabilities (CVE-2019-14811, CVE-2019-14812, CVE-2019-14813, CVE-2019-14817), e lumellang ka ho theha sehokelo ho ".forceput" ho feta mokhoa oa ho itšehla thajana oa "-dSAFER" . Ha o sebetsana le litokomane tse entsoeng ka mokhoa o khethehileng, mohlaseli a ka khona ho fumana likahare tsa tsamaiso ea lifaele 'me a sebelisa khoutu e sa lebelloang tsamaisong (mohlala, ka ho kenya litaelo ho ~/.bashrc kapa ~/.profile). Tokiso e fumaneha e le li-patches (1, 2). U ka latela ho fumaneha ha lintlafatso tsa sephutheloana likhatisong maqepheng ana: Debian, Fedora, Botho, SUSE/openSUSE, RHEL, Arch, ROSE, FreeBSD.

A re u hopotse hore bofokoli ho Ghostscript bo baka kotsi e kholo, kaha sephutheloana sena se sebelisoa lits'ebetsong tse ngata tse tsebahalang bakeng sa ho sebetsana le liforomo tsa PostScript le tsa PDF. Mohlala, Ghostscript e bitsoa nakong ea popo ea li-thumbnail tsa komporo, indexing ea data e ka morao, le phetoho ea setšoantšo. Bakeng sa tlhaselo e atlehileng, maemong a mangata ho lekane ho khoasolla faele ka ho sebelisa hampe kapa ho bala bukana ka eona ho Nautilus. Bofokoli ho Ghostscript le bona bo ka sebelisoa hampe ka li-processor tsa litšoantšo tse ipapisitseng le liphutheloana tsa ImageMagick le GraphicsMagick ka ho li fetisetsa faele ea JPEG kapa PNG e nang le khoutu ea PostScript sebakeng sa setšoantšo (faele e joalo e tla sebetsoa ka Ghostscript, kaha mofuta oa MIME o tsejoa ke dikahare, mme ntle le ho itshetleha ka katoloso).

Source: opennet.ru

Eketsa ka tlhaloso