oss-sec mailing list archives
Re: CVE Request - multiple ghostscript -dSAFER sandbox problems
From: Bob Friesenhahn <bfriesen () simple dallas tx us>
Date: Wed, 5 Oct 2016 12:24:46 -0500 (CDT)
On Wed, 5 Oct 2016, Hanno Böck wrote:
I was surprised to see evince in this list. It uses poppler for pdf and libspectre for postscript, so there seems to be no use of ghostscript (maybe in an older version).
There is only one open-sourced Postscript interpreter (Ghostscript) that I am aware of.
There are perhaps two open-sourced PDF interpreters available (Ghostscript and derivatives of 'xpdf' like 'poppler').
ImageMagick and GraphicsMagick are depending on Ghostscript.Since Postscript is a format commonly sent to printers, many programs produce it, and thus it is used as an intermediate format. The typical use case is for ImageMagick/GraphicsMagick to automatically run an external utility which converts from the format being read into Postscript, then Ghostscript is used to convert it to a raster format (e.g. PNM), and then the raster format is read by ImageMagick/GraphicsMagick before being output to the final format.
Disabling Ghostscript or requiring user input to proceed will cause a lot of breakage.
Bob -- Bob Friesenhahn bfriesen () simple dallas tx us, http://www.simplesystems.org/users/bfriesen/ GraphicsMagick Maintainer, http://www.GraphicsMagick.org/
Current thread:
- CVE Request - multiple ghostscript -dSAFER sandbox problems Tavis Ormandy (Oct 05)
- Re: CVE Request - multiple ghostscript -dSAFER sandbox problems Hanno Böck (Oct 05)
- Re: CVE Request - multiple ghostscript -dSAFER sandbox problems Tavis Ormandy (Oct 05)
- Re: CVE Request - multiple ghostscript -dSAFER sandbox problems Tavis Ormandy (Oct 05)
- Re: CVE Request - multiple ghostscript -dSAFER sandbox problems Tavis Ormandy (Oct 05)
- Re: CVE Request - multiple ghostscript -dSAFER sandbox problems Hanno Böck (Oct 05)
- Re: CVE Request - multiple ghostscript -dSAFER sandbox problems Tavis Ormandy (Oct 05)
- Re: CVE Request - multiple ghostscript -dSAFER sandbox problems Hanno Böck (Oct 05)
- Re: CVE Request - multiple ghostscript -dSAFER sandbox problems Bob Friesenhahn (Oct 05)
- Re: CVE Request - multiple ghostscript -dSAFER sandbox problems Hanno Böck (Oct 05)
- Re: CVE Request - multiple ghostscript -dSAFER sandbox problems Jakub Wilk (Oct 05)
- Re: CVE Request - multiple ghostscript -dSAFER sandbox problems Florian Weimer (Oct 05)
- Re: Re: CVE Request - multiple ghostscript -dSAFER sandbox problems Cedric Buissart (Oct 19)
- Re: CVE Request - multiple ghostscript -dSAFER sandbox problems Tavis Ormandy (Oct 11)
- Re: CVE Request - multiple ghostscript -dSAFER sandbox problems cve-assign (Oct 11)