LWN.net Logo

ghostscript: PostScript code execution

Package(s):ghostscript CVE #(s):CVE-2010-4820
Created:February 3, 2012 Updated:February 8, 2012
Description: From the Red Hat advisory:

Ghostscript included the current working directory in its library search path by default. If a user ran Ghostscript without the "-P-" option in an attacker-controlled directory containing a specially-crafted PostScript library file, it could cause Ghostscript to execute arbitrary PostScript code. With this update, Ghostscript no longer searches the current working directory for library files by default.

Alerts:
Red Hat RHSA-2012:0096-01 2012-02-02
Red Hat RHSA-2012:0095-01 2012-02-02
CentOS CESA-2012:0095 2012-02-03
CentOS CESA-2012:0095 2012-02-03
CentOS CESA-2012:0096 2012-02-03
Scientific Linux SL-ghos-20120203 2012-02-03
Scientific Linux SL-ghos-20120203 2012-02-03
Oracle ELSA-2012-0095 2012-02-03
Oracle ELSA-2012-0095 2012-02-03
Oracle ELSA-2012-0096 2012-02-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds