CVE Vulnerabilities

CVE-2000-1163

Published: Jan 09, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript.

Affected Software

NameVendorStart VersionEnd Version
GhostscriptAladdin_enterprises4.3 (including)4.3 (including)
GhostscriptAladdin_enterprises5.10.10 (including)5.10.10 (including)
GhostscriptAladdin_enterprises5.10.15 (including)5.10.15 (including)
GhostscriptAladdin_enterprises5.10cl (including)5.10cl (including)
GhostscriptAladdin_enterprises5.50 (including)5.50 (including)

References