Ubuthathaka obutsha kwi-Ghostscript

Uthotho lobuthathaka aluyeki (1, 2, 3, 4, 5, 6) ngaphakathi Amagama abhaliweyo, isethi yezixhobo zokusebenza, ukuguqula kunye nokuvelisa amaxwebhu kwi-PostScript kunye neefomathi ze-PDF. Njengobuthathaka obudlulileyo ingxaki entsha (I-CVE-2019-10216) ivumela, xa kusetyenzwa amaxwebhu ayilwe ngokukodwa, ukuba idlule i-"-dSAFER" imo yokubeka yodwa (ngobuchule nge ".buildfont1") kwaye ifumane ufikelelo kwimixholo yenkqubo yefayile, engasetyenziselwa ukuququzelela uhlaselo ukwenza ikhowudi engafanelekanga. kwindlela (umzekelo, ngokongeza imiyalelo kwi ~ /.bashrc okanye ~/.profile). Ulungiso luyafumaneka njenge isiqwenga. Ungalandelela ukufumaneka kohlaziyo lwephakheji kunikezelo kula maphepha: Debian, Fedora, Ubuntu, SUSE/openSUSE, RHEL, igophe, FreeBSD.

Masikukhumbuze ukuba ubuthathaka kwi-Ghostscript kubangela ingozi eyongeziweyo, kuba le phakheji isetyenziswa kwizicelo ezininzi ezidumileyo zokusetyenzwa kwePostScript kunye neefomathi zePDF. Umzekelo, i-Ghostscript ibizwa ngexesha lokudalwa kwe-thumbnail ye-desktop, isalathisi sedatha yangasemva, kunye nokuguqulwa komfanekiso. Kuhlaselo oluyimpumelelo, kwiimeko ezininzi kwanele ukukhuphela ngokulula ifayile nge-exploit okanye ukukhangela ulawulo ngayo kwiNautilus. Ubuthathaka kwi-Ghostscript bunokuxhatshazwa ngabaqhubekekisi bemifanekiso esekwe kwi-ImageMagick kunye neepakethe ze-GraphicsMagick ngokugqithisela iJPEG okanye ifayile ye-PNG equlathe ikhowudi ye-PostScript endaweni yomfanekiso (ifayile elolo hlobo iya kucutshungulwa kwi-Ghostscript, ekubeni udidi lwe-MIME lubonwa yi umxholo, kwaye ngaphandle kokuxhomekeka ekwandisweni).

umthombo: opennet.ru

Yongeza izimvo