Back to search
CVE-2010-2055
Published: Jul 22, 2010
Modified: Aug 7, 2024
PUBLISHED
Description
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
66247
vdb-entry
x_refsource_OSVDB
40532
third-party-advisory
x_refsource_SECUNIA
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583183
x_refsource_CONFIRM
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583316
x_refsource_CONFIRM
20100526 Re: Ghostscript 8.64 executes random code at startup
mailing-list
x_refsource_BUGTRAQ
RHSA-2012:0095
vendor-advisory
x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=599564
x_refsource_CONFIRM
GLSA-201412-17
vendor-advisory
x_refsource_GENTOO
ADV-2010-1757
vdb-entry
x_refsource_VUPEN
http://savannah.gnu.org/forum/forum.php?forum_id=6368
x_refsource_CONFIRM
20100526 Re: Ghostscript 8.64 executes random code at startup
mailing-list
x_refsource_BUGTRAQ
FEDORA-2010-10642
vendor-advisory
x_refsource_FEDORA
20100522 Ghostscript 8.64 executes random code at startup
mailing-list
x_refsource_BUGTRAQ
http://bugs.ghostscript.com/show_bug.cgi?id=691350
x_refsource_CONFIRM
40452
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2010:014
vendor-advisory
x_refsource_SUSE
https://bugzilla.novell.com/show_bug.cgi?id=608071
x_refsource_CONFIRM
40475
third-party-advisory
x_refsource_SECUNIA
FEDORA-2010-10660
vendor-advisory
x_refsource_FEDORA
20100526 Re: Ghostscript 8.64 executes random code at startup
mailing-list
x_refsource_BUGTRAQ
http://bugs.ghostscript.com/show_bug.cgi?id=691339
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now