ghostscript: multiple critical...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

I sent the following mail to the oss-security mailing list: http://seclists.org/oss-sec/2018/q3/142 These are critical and trivial remote code execution bugs in things like ImageMagick, Evince, GIMP, and most other PDF/PS tools. Hello, this was discussed on the distros list, but it was suggested to move discussion to oss-security. You might recall I posted a bunch of -dSAFER sandbox escapes in ghostscript a few years ago: http://seclists.org/oss-sec/2016/q4/29 I found a few file disclosure, shell command execution, memory corruption and type confusion bugs. There was also one that was found exploited in the wild. There was also a similar widely exploited issue that could be exploited identically. TL;DR: I *strongly* suggest that distributions start disabling PS, EPS, PDF and XPS coders in policy.xml by default. ``` $ convert input.jpg output.gif uid=1000(taviso) gid=1000(taviso) groups=1000(taviso),10(wheel) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 ``` I've...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息