LWN.net Logo

Ghostscript arbitrary command execution vulnerability

Package(s):ghostscript CVE #(s):CAN-2002-0363
Created:June 5, 2002 Updated:June 12, 2002
Description: Ghostscript may be used to execute arbitrary commands with a maliciously formed PostScript file. Since ghostscript is frequently used while printing documents, updating is strongly recommended.

The vulnerability has been fixed in the 6.53 source release of GNU Ghostscript.

Alerts:
SCO Group CSSA-2002-026.0 2002-06-11
Yellow Dog YDU-20020606-4 2002-06-06
Eridani ERISA-2002:022 2002-06-05
Red Hat RHSA-2002:083-22 2002-06-03

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds