Ghostscript Failed Restore Command Execution
Posted by deepcore on September 7, 2018 – 8:35 am
This Metasploit module exploits a -dSAFER bypass in Ghostscript to execute arbitrary commands by handling a failed restore (grestore) in PostScript to disable LockSafetyParams and avoid invalidaccess. This vulnerability is reachable via libraries such as ImageMagick, and this module provides the latest vector for Ghostscript.
Post a reply
You must be logged in to post a comment.