Vulnerability Description
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Artifex | Afpl Ghostscript | 6.0 |
| Artifex | Ghostscript Fonts | 6.0 |
| Artifex | Gpl Ghostscript | <= 8.71 |
Related Weaknesses (CWE)
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583183
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583316
- http://bugs.ghostscript.com/show_bug.cgi?id=691339Exploit
- http://bugs.ghostscript.com/show_bug.cgi?id=691350
- http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043913.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043948.html
- http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html
- http://savannah.gnu.org/forum/forum.php?forum_id=6368
- http://secunia.com/advisories/40452Vendor Advisory
- http://secunia.com/advisories/40475Vendor Advisory
- http://secunia.com/advisories/40532Vendor Advisory
- http://security.gentoo.org/glsa/glsa-201412-17.xml
- http://www.osvdb.org/66247
- http://www.securityfocus.com/archive/1/511433
- http://www.securityfocus.com/archive/1/511472Exploit
FAQ
What is CVE-2010-2055?
CVE-2010-2055 is a vulnerability with a CVSS score of 7.2 (HIGH). Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improp...
How severe is CVE-2010-2055?
CVE-2010-2055 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2055?
Check the references section above for vendor advisories and patch information. Affected products include: Artifex Afpl Ghostscript, Artifex Ghostscript Fonts, Artifex Gpl Ghostscript.