9 ms·
Critical RCE found in popular Ghostscript open-source PDF library
- hulitu 3y agoRCE ? Since when is ghostscript a web browser ?
- ok123456 3y agoMaybe if you're using it for NeWS.
- yjftsjthsd-h 3y agoIf an untrusted file can run postscript on your NeWS display server, then yes, you are extremely compromised. (Rather like `curl|sh`, I question if that's meaningful even if it is trivially true.)
- lolinder 3y agoRCE (remote code execution) vulnerabilities aren't restricted to web browsers. All it means is "an attacker can execute arbitrary code on the victim's computer". In this case, many people use ghostscript as a server-side component for managing PDF uploads, so an attacker could theoretically upload a malicious PDF and gain control over those servers. Examples of non-browser RCEs: * Microsoft Exchange Server and Windows: https://krebsonsecurity.com/2022/01/wormable-flaw-leads-january-2022-patch-tuesday/ https://krebsonsecurity.com/2022/01/wormable-flaw-leads-janu... * Microsoft Office: https://krebsonsecurity.com/2023/07/apple-microsoft-patch-tuesday-july-2023-edition/ https://krebsonsecurity.com/2023/07/apple-microsoft-patch-tu... * Apache Struts: https://krebsonsecurity.com/2018/08/experts-urge-rapid-patching-of-struts-bug/ https://krebsonsecurity.com/2018/08/experts-urge-rapid-patch...
- codetrotter 3y agoDoesn’t have to be a web browser to be vulnerable to remote code execution. But it is a valid question to ask why it counts as an RCE. On the one hand, they say: > Successful exploitation requires user interaction by the victim. And on the other hand > Local: No > Remote: Yes https://vuldb.com/?id.197290 https://vuldb.com/?id.197290 The bugzilla bug tracker for Ghostscript is currently down for maintenance, so can’t browse it for more details at the moment. But I wonder if for example a web server that uses Ghostscript to convert documents could be vulnerable. In which case RCE classification makes sense. Otherwise, do they count it as RCE even if it involves tricking a user into opening a bad file using Ghostscript? If navigating to a bad website with a vulnerable browser counts as RCE in other cases then perhaps opening a bad file with Ghostscript counts as RCE as well?
- tedunangst 3y agoIt's remote in the sense the file comes from elsewhere. It's a problem even if you trust your user (yourself), because you probably open files from untrusted people. Local priv escalation is something like a root exploit where you don't trust the user.
- codetrotter 3y agoThanks, that makes sense :)
- thaumasiotes 3y ago> But it is a valid question to ask why it counts as an RCE. It's an RCE because the form of the attack is that Ghostscript ends up executing code that isn't part of Ghostscript. Code is written outside the system ("remote code") and then executed inside it ("execution"). A malicious PDF that causes Ghostscript to execute arbitrary code would contrast with a malicious PDF that causes Ghostscript to execute inappropriate code that is nevertheless part of Ghostscript. The RCE allows the attacker to do anything the computer can do. The other one allows them to do something (but not necessarily anything) that Ghostscript can do.
- worthless-trash 3y agoMost attacker controlled execution code does not originate inside the binary, most buffer overflows inject shellcode. Using execution code from outside the binary does not make it an RCE.
- wang_li 3y ago> But I wonder if for example a web server that uses Ghostscript to convert documents could be vulnerable. In which case RCE classification makes sense. If this is an RCE then all bugs that could lead to code execution are RCEs because, theoretically, I can put some piece of code in front of it that listens on the network. This is an unexpected code execution bug. Calling it RCE would suggest that systems that let you double-click on documents to open them are RCEs because I can name an elf executable AliceAndBobAtTheBeach.jpg.
- nicolas_17 3y agoThe article is from yesterday and at first it scared me into thinking it was yet another vulnerability. Turns out it's from weeks ago and Debian patched it 10 days ago. Whew.
- Spooky23 3y agoI would not exhale too fast. Ghostscript is embedded all over the place.
- favorited 3y agoMy favorite RCE, FORCEDENTRY[0], also involved PDFs. It was the first time I was truly in awe of an exploit. Through a combination of (1) an integer overflow in an open-source PDF compression library, (2) a Turing-complete compression codec, and (3) CoreGraphics noticing that the "gif" in your iMessage is actually a PDF and helpfully decoding it for you, NSO was able to bootstrap a purpose-built virtual machine, upon which they ran their sandbox-escape. I highly recommend reading this post[1] by Project Zero if you haven't already. [0]https://en.wikipedia.org/wiki/FORCEDENTRY https://en.wikipedia.org/wiki/FORCEDENTRY [1]https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
- arkadiyt 3y agoI've said it before and I'll say it again: ghostscript will never be safe, ever. If you must run it then make it 100% isolated, for instance in a lambda with no api credentials or IAM permissions, & do s3 input/output by passing presigned urls. Make it ok to have RCE.
- cjbprime 3y agoAnd make sure never to re-use one lambda function or container to process more than a single customer's data, to avoid the RCE gaining access to whatever file next gets uploaded :)
- worthless-trash 3y agoIs there a 'ghostscript' server I dont know about ? Where is the "Remote" in this RCE ?
- tinus_hn 3y agoAirPrint is ‘send pdf to the printer and it prints’ and there is a million cloud or cloud like services that use Ghostscript to create thumbnails.
- justinclift 3y agoGhostscript seems to be often used as a backend tool in automated pipelines. So, the whole RCE thing is probably pretty true in this case.
- worthless-trash 3y agoIf we classify flaws this way though, everything is access able to be accessed via ssh, etc. CVE flaws have an an 'environment' section for exactly this purpose.
- justinclift 3y agoYeah, that's a fair point. They might be stressing the "remote" bit though, just so it sinks in for people using it as part of a document conversion pipeline or something. But, that's just me guessing wildly. :)
- rlupi 3y agoI wonder if it is used in phones.
- deleted 3y ago[deleted]
- eviks 3y agoIs there any good replacement to this awful PDF format on the horizon?
- SanchoPanda 3y agoThere is not. PDF is more ingrained into our tech then ever before. Something like a a quarter or a third of the web is pdfs, it is the default archival format, and the only remotely plausible competitor for the core function of PDF (it more or less looks the same to me as it does to you and you for sure have the software to open it one way or another) is maybe HTML/CSS. There are competitors for the 8,000 other uses of PDFs but only one at a time.
- ASalazarMX 3y agoDJVu is the closest equivalent, but it hasn't evolved enough to outshine PDFs in all their uses.