Ghostscriptí§ÒâÎļþ¶ÁдÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-10-11

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-17961£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Ghostscript version <= 9.26


Îó²î¸ÅÊö


GhostscriptÊÇAdobe PostScriptºÍPDFµÄÚ¹ÊÍÓïÑÔ£¬Ðí¶àͼƬ´¦Öóͷ£¿â¾ùÓÐÒýÓ㬳£¼ûµÄÓÐ ImageMagick¡¢Python-Matplotlib¡¢Latex2htmlµÈ¡£


±¾´Î·¢Ã÷µÄÎó²î¿ÉʹGhostscript µÄÇ徲ɳÏä±»ÈÆ¹ý£¬¶ñÒâ¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâµÄͼƬÄÚÈÝ£¬¿ÉÔì³Éí§ÒâÎļþ¶Áд¡£Ê¹ÓÃGhostscriptµÄWebÓ¦Óñ£´æ±»Ô¶³ÌÏÂÁî¹¥»÷µÄΣº¦¡£

×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


Îó²îµ¼ÖÂËùÓÐÒýÓÃghostscriptµÄÉÏÓÎÓ¦ÓÃÊܵ½Ó°Ïì¡£ ³£¼ûÓ¦ÓÃÈçÏ£º

Imagemagick¡¢libmagick¡¢graphicsmagick¡¢gimp¡¢python-matplotlib¡¢texlive-core¡¢texmacs¡¢latex2html¡¢latex2rtfµÈ


Îó²îÑéÖ¤


EXP£ºhttps://www.exploit-db.com/exploits/45573/

¹Ù·½¶Ô.forceputµÄʹÓÃÏÈÈÝ£¬Äܹ»Ç¿ÖƸüÐÂdictÖеÄÖµ¡£Õâ´ÎµÄÎó²îÖ÷ÒªÔµ¹ÊÔ­ÓÉÒ²¾ÍÊÇÔÚ´¥·¢¹ýʧµÄʱ¼äÓÉÓڽṹ³ö.forceputÁô±£´æÕ»ÖУ¬È»ºó±»×¢²á³ÉÏÂÁîforceput½ø¶ø¶Ôsystemdict¾ÙÐÐÐ޸ġ£×îÖÕµÖ´ïbypass saferÒÔ¼°¿ªÆôÎļþ¶ÁдȨÏ޵ȲÙ×÷¡£


Ubuntu 16.04 ÍâµØÊ¹ÓÃ×îаæ GhostScript 9.25 ²âÊÔ PoC£¬ÀֳɶÁÈ¡ /etc/passwd Îļþ£¬ÒÔ¼°Ïò ~/.bashrc дÈëÏÂÁîºóÃÅ£º

×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


ImageMagick 7.0.8-12 ²âÊÔ£º


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


ÐÞ¸´½¨Òé


Ghostscript¹Ù·½ÒѸø³ö»º½â²½·¥£¬Çëʵʱ¸üУº
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=a54c9e61e7d
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=a6807394bd94
ÎÞ·¨¸üеĿÉͨ¹ýÐÞ¸Äpolicy.xml½ûÓÃPS, EPS, PDF and XPS coders£¨»áÔì³ÉÏà¹Ø¹¦Ð§²»¿ÉʹÓã©
È磺ÐÞ¸ÄImageMagickµÄpolicyÎļþ£¬Ä¬ÈÏλÖÃΪ/etc/ImageMagick-7/policy.xml
Ìí¼ÓÈçÏÂÄÚÈÝ£º
<policymap>
<policydomain="coder" rights="none" pattern="PS" />
<policydomain="coder" rights="none" pattern="EPS" />
<policydomain="coder" rights="none" pattern="PDF" />
<policydomain="coder" rights="none" pattern="XPS" />
</policymap>

ÈôÊDz»ÐèҪʹÓÃGhostScript£¬¿ÉÐ¶ÔØ¡£


²Î¿¼Á´½Ó


https://mailclark.ai/email/original/16819467/593541/mxzCj2eeqRd2DhZOU0Es1rJVQeg?from_name=Tavis%20Ormandy