PT-2014-2083 · Artifex+2 · Ghostscript+2
Ramon De C Valle
·
Publicado
2012-02-02
·
Atualizado
2014-11-02
·
CVE-2010-4820
CVSS v2.0
4.4
Média
| Vetor | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ghostscript version 8.62
Description
The issue allows local users to execute arbitrary PostScript code via a Trojan horse PostScript library file in the Encoding/ directory under the current working directory.
Recommendations
For Ghostscript version 8.62, consider restricting access to the Encoding/ directory to prevent the execution of arbitrary PostScript code until a patch is available. As a temporary workaround, avoid using the current working directory for PostScript library files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Ghostscript
Red Hat