Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2010-07-22 05:43
Updated : 2015-01-09 23:44
NVD link : CVE-2010-2055
Mitre link : CVE-2010-2055
CVE.ORG link : CVE-2010-2055
JSON object : View
Products Affected
artifex
- ghostscript_fonts
- afpl_ghostscript
- gpl_ghostscript
CWE
CWE-17
DEPRECATED: Code