A ghostscript package fixing a command execution vulnerability is now available.
GNU Ghostscript is an interpreter for the PostScript language, and is often used when printing to printers that do not have their own built-in PostScript interpreter. A flaw has been discovered in the way Ghostscript validates some PostScript commands. This flaw allows an attacker to force commands to be executed by a print spooler by submitting a malicious print job. Note that using the -dSAFER option is not sufficient to prevent command execution. Users of Ghostscript are advised to upgrade to these updated packages, which are not vulnerable to this issue.
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center