oss-sec mailing list archives

Re: Re: More Ghostscript Issues: Should we disable PS coders in policy.xml by default?


From: Bob Friesenhahn <bfriesen () simple dallas tx us>
Date: Tue, 21 Aug 2018 10:00:26 -0500 (CDT)

On Tue, 21 Aug 2018, Tavis Ormandy wrote:

I think those thumbnails should be disabled, but you've probably noticed I
think everything related to untrusted ghostscript should be disabled :-)

I have posted to the GraphicsMagick Announcements mailing list regarding your findings (with a link to this list) and suggested that a fool-proof solution is that Ghostscript should be uninstalled.

Uninstalling Ghostscript entirely might cause software using libgs to not execute at all unless a stub library is put in its place.

Dependencies on Ghostscript are much larger than one would initially think due to Postscript being the traditional output from Unix software for "printing" and thus it is used as an intermediate format in order to convert between formats. EPS content is also embedded in some other formats.

Bob
--
Bob Friesenhahn
bfriesen () simple dallas tx us, http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/


Current thread: