Ghostscript and security (CVE-2019-10216)

Bob Friesenhahn <[email protected]> Mon, 12 Aug 2019 09:55:06 -0500 (CDT)
Newsgroups gmane.comp.video.graphicsmagick.announce
Message-ID <[email protected]>
There has been yet another security bulletin issued (CVE-2019-10216) 
related to Ghostscript not being secure when opening Postscript files 
(see https://seclists.org/oss-sec/2019/q3/133).

As a reminder, GraphicsMagick uses Ghostscript to read Postscript (and 
PDF) files.  A suitably-crafted Postscript file might gain access to 
arbitrary files on the system when it is opened.  Postscript is a 
high-level language so complex programs may be expressed in it.

It is not clear (to me) if it is possible to exercise this exploit via 
a PDF file, although it involves Postscript Type 1 font handling, and 
these types of fonts could be used by a PDF file.  Given that it is 
not clear, it is wise to assume that PDF is also at risk.

Please be aware that you should update your Ghostscript installation 
to a fixed version if untrusted files may be opened.

Bob
-- 
Bob Friesenhahn
[email protected], http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/
Public Key,     http://www.simplesystems.org/users/bfriesen/public-key.txt