CVE Vulnerabilities

CVE-2010-2055

Published: Jul 22, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
4.4 MODERATE
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.

Affected Software

NameVendorStart VersionEnd Version
Afpl_ghostscriptArtifex6.0 (including)6.0 (including)
Afpl_ghostscriptArtifex6.01 (including)6.01 (including)
Afpl_ghostscriptArtifex6.50 (including)6.50 (including)
Afpl_ghostscriptArtifex7.00 (including)7.00 (including)
Afpl_ghostscriptArtifex7.03 (including)7.03 (including)
Afpl_ghostscriptArtifex7.04 (including)7.04 (including)
Afpl_ghostscriptArtifex8.00 (including)8.00 (including)
Afpl_ghostscriptArtifex8.11 (including)8.11 (including)
Afpl_ghostscriptArtifex8.12 (including)8.12 (including)
Afpl_ghostscriptArtifex8.13 (including)8.13 (including)
Afpl_ghostscriptArtifex8.14 (including)8.14 (including)
Afpl_ghostscriptArtifex8.50 (including)8.50 (including)
Afpl_ghostscriptArtifex8.51 (including)8.51 (including)
Afpl_ghostscriptArtifex8.52 (including)8.52 (including)
Afpl_ghostscriptArtifex8.53 (including)8.53 (including)
Afpl_ghostscriptArtifex8.54 (including)8.54 (including)
Ghostscript_fontsArtifex6.0 (including)6.0 (including)
Ghostscript_fontsArtifex8.11 (including)8.11 (including)
Gpl_ghostscriptArtifex*8.71 (including)
Gpl_ghostscriptArtifex8.01 (including)8.01 (including)
Gpl_ghostscriptArtifex8.15 (including)8.15 (including)
Gpl_ghostscriptArtifex8.50 (including)8.50 (including)
Gpl_ghostscriptArtifex8.51 (including)8.51 (including)
Gpl_ghostscriptArtifex8.54 (including)8.54 (including)
Gpl_ghostscriptArtifex8.56 (including)8.56 (including)
Gpl_ghostscriptArtifex8.57 (including)8.57 (including)
Gpl_ghostscriptArtifex8.60 (including)8.60 (including)
Gpl_ghostscriptArtifex8.61 (including)8.61 (including)
Gpl_ghostscriptArtifex8.62 (including)8.62 (including)
Gpl_ghostscriptArtifex8.63 (including)8.63 (including)
Gpl_ghostscriptArtifex8.64 (including)8.64 (including)
Gpl_ghostscriptArtifex8.70 (including)8.70 (including)
Red Hat Enterprise Linux 5RedHatghostscript-0:8.70-6.el5_7.6*
Red Hat Enterprise Linux 6RedHatghostscript-0:8.70-11.el6_2.6*
GhostscriptUbuntuhardy*
GhostscriptUbuntujaunty*
GhostscriptUbuntukarmic*
GhostscriptUbuntulucid*
GhostscriptUbuntumaverick*
GhostscriptUbuntuupstream*
Gs-afplUbuntudapper*
Gs-espUbuntudapper*
Gs-gplUbuntudapper*

References