Ukuba sengozini okusha ku-Ghostscript

Uchungechunge lobuthakathaka alumi (1, 2, 3, 4, 5, 6) ku I-Ghostscript, isethi yamathuluzi okucubungula, ukuguqula kanye nokukhiqiza imibhalo ngefomethi ye-PostScript kanye ne-PDF. Njengobuthakathaka obudlule inkinga entsha (I-CVE-2019-10216) ivumela, lapho kucutshungulwa amadokhumenti aklanywe ngokukhethekile, ukweqa imodi yokuzihlukanisa ye-“-dSAFER” (ngokusebenzisa ukukhohlisa nge-“.buildfont1”) futhi ithole ukufinyelela kokuqukethwe kwesistimu yefayela, engasetshenziswa ukuhlela ukuhlasela ukuze kwenziwe ikhodi engafanele. ohlelweni (isibonelo, ngokwengeza imiyalo ku- ~ /.bashrc noma ~/.profile). Ukulungiswa kuyatholakala njenge isichibi. Ungakwazi ukulandelela ukutholakala kwezibuyekezo zephakheji ekusatshalalisweni kulawa makhasi: Debian, Fedora, Ubuntu, SUSE/openSUSE, RHEL, Arch, I-FreeBSD.

Ake sikukhumbuze ukuthi ubungozi ku-Ghostscript bubeka ingozi eyengeziwe, njengoba le phakheji isetshenziswa ezinhlelweni eziningi ezidumile zokucubungula amafomethi we-PostScript kanye ne-PDF. Isibonelo, i-Ghostscript ibizwa ngesikhathi sokudala isithonjana sedeskithophu, ukukhomba idatha yangemuva, nokuguqulwa kwesithombe. Ukuhlasela okuphumelelayo, ezimweni eziningi kwanele ukumane ulande ifayela nge-exploit noma upheqa umkhombandlela ngalo ku-Nautilus. Ubungozi ku-Ghostscript bungaphinda busetshenziswe ngokucubungula izithombe ngokusekelwe kumaphakheji e-ImageMagick kanye ne-GraphicsMagick ngokuwadlulisela ifayela le-JPEG noma le-PNG eliqukethe ikhodi ye-PostScript esikhundleni sesithombe (ifayela elinjalo lizocutshungulwa ku-Ghostscript, njengoba uhlobo lwe-MIME lubonwa okuqukethwe, futhi ngaphandle kokuthembela esandisweni).

Source: opennet.ru

Engeza amazwana