Ghostscript and security (CVE-2019-10216)
Bob Friesenhahn <[email protected]> Mon, 12 Aug 2019 09:55:06 -0500 (CDT)
| Newsgroups | gmane.comp.video.graphicsmagick.announce |
|---|---|
| Message-ID | <[email protected]> |
There has been yet another security bulletin issued (CVE-2019-10216) related to Ghostscript not being secure when opening Postscript files (see https://seclists.org/oss-sec/2019/q3/133). As a reminder, GraphicsMagick uses Ghostscript to read Postscript (and PDF) files. A suitably-crafted Postscript file might gain access to arbitrary files on the system when it is opened. Postscript is a high-level language so complex programs may be expressed in it. It is not clear (to me) if it is possible to exercise this exploit via a PDF file, although it involves Postscript Type 1 font handling, and these types of fonts could be used by a PDF file. Given that it is not clear, it is wise to assume that PDF is also at risk. Please be aware that you should update your Ghostscript installation to a fixed version if untrusted files may be opened. Bob -- Bob Friesenhahn [email protected], http://www.simplesystems.org/users/bfriesen/ GraphicsMagick Maintainer, http://www.GraphicsMagick.org/ Public Key, http://www.simplesystems.org/users/bfriesen/public-key.txt