19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

dated August 24 1995 (see also S 2.35 Obtaining information on security<br />

flaws of the system).<br />

For example, this problem affects all ghostscript versions of Aladdin prior to<br />

3.22beta and the GNU versions up to and including 2.6.2. In older ghostscript<br />

versions there may also be further PostScript commands with which it is<br />

possible to modify files. Only ghostscript versions where these problems have<br />

been overcome should be used.<br />

From version 1.5 onwards, the ghostview PostScript interpreter offers the -<br />

safer option, which activates the security functions of ghostscript. Versions<br />

earlier than 1.5 do not offer this protection, and should be replaced by the<br />

current version.<br />

Similar problems can also occur in the case of PDF files. PDF files which can<br />

be read with Acrobat Reader freeware are often available in the Internet.<br />

Functions such as program calls can be embedded in PDF files, and can pose a<br />

security risk to the files of the local <strong>IT</strong> system. <strong>The</strong>se embedded functions can<br />

be started when a document is opened or via action triggers by moving<br />

through the document, without the reader being aware of this.<br />

To avoid this, PDF files should only be read with viewers such as ghostscript<br />

which are not able to process this functionality, or with the latest version of<br />

Acrobat Reader or Acrobat Exchange, which inform the user about the<br />

presence of any macros and require explicit approval of their execution.<br />

Additional controls:<br />

- Does the virus checker program in use also detect macro viruses?<br />

- Was a check made to see whether the -dSAFER option is activated in the<br />

PostScript interpreters being used?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!