|
|
| |
|
| |
ghostscript: PostScript code execution
| Package(s): | ghostscript |
CVE #(s): | CVE-2010-4820
|
| Created: | February 3, 2012 |
Updated: | February 8, 2012 |
| Description: |
From the Red Hat advisory:
Ghostscript included the current working directory in its library search
path by default. If a user ran Ghostscript without the "-P-" option in an
attacker-controlled directory containing a specially-crafted PostScript
library file, it could cause Ghostscript to execute arbitrary PostScript
code. With this update, Ghostscript no longer searches the current working
directory for library files by default. |
| Alerts: |
|
( Log in to post comments)
|
|
|