What is Nostr?
Bill Mill /
npub1k3c…3fyp
2024-07-03 12:33:38

Bill Mill on Nostr: If you have ghostscript *anywhere* in your production services, you are probably ...

If you have ghostscript *anywhere* in your production services, you are probably vulnerable to a shockingly trivial remote shell execution, and you should upgrade it or remove it from your production systems.

https://codeanlabs.com/blog/research/cve-2024-29510-ghostscript-format-string-exploitation/

One thing to note is that imagemagick will automatically forward postscript files to ghostscript, so if you are using imagemagick anywhere you are probably vulnerable. (If you are using javascript libraries to process images, you probably are!)
Author Public Key
npub1k3cxq9qqnjeephe0f3dzs37ur9d60qwhvxasnvzalqxp23dktdgs8n3fyp