Releases PoC for exploit that affects servers

The Proof-of-concept (PoC) of an exploit was posted online over the weekend about a Ghostscript vulnerability that compromises all component-based servers.

The PoC was published by Vietnamese security researcher Nguyen The Duc in GitHub and has been confirmed to work by several leading security researchers.code php html

Ghostscript was released in 1988 and is a small library that allows applications to edit PDF documents and PostScript-based files.

Ghostscript is also used by the server, and is usually included in image conversion and file editing tools, such as the popular ImageMagick.

The PoC released by Nguyen allows an intruder to upload a malware SVG that is supposed to go for image processing, but runs maliciously to the underlying operating system.

Nguyen may have been the one who publicly released PoC, but he did not discover the vulnerability.

Την ανακάλυψε ο Emil Lerner CTO και ιδρυτής της Wunderfund, ο οποίος χρησιμοποίησε το σφάλμα πέρυσι για να κερδίσει bug bounties από εταιρείες όπως τις Airbnb, and .

This is the second time the Ghostscript project has been in the news for security flaws. In August 2018, a Google security researcher made several critical discoveries points in the Ghostscript library that Artifex (the company that develops it) failed to patch in time. However, the company released fixes two days after the vulnerabilities were made public.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.
Proof-of-concept, proof of concept ελληνικά, proof of concept example, exploit, poc, iguru, iguru.gr

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).