oss-sec mailing list archives

Re: ghostscript: bypassing executeonly to escape -dSAFER sandbox (CVE-2018-17961)


From: Leonid Isaev <leonid.isaev () jila colorado edu>
Date: Tue, 9 Oct 2018 09:30:06 -0600

On Tue, Oct 09, 2018 at 06:58:39AM -0700, Tavis Ormandy wrote:
Full working exploit that works in the last few versions is attached,
viewing it in evince, imagemagick, gimp, okular, etc should add a line to
~/.bashrc.

Add zathura to the above list :)

p.s. plz can we deprecate untrusted postscript :(

Which means any postscript file downloaded from the internet... Then how should
people read arXiv.org, for example?

Thanks,
L.

-- 
Leonid Isaev


Current thread: