CVE-2010-2055
Publication date 22 July 2010
Last updated 24 July 2024
Ubuntu priority
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.
Status
Package | Ubuntu Release | Status |
---|---|---|
ghostscript | ||
gs-afpl | ||
gs-esp | ||
gs-gpl | ||
Notes
mdeslaur
There are three different issues here: 1- -P is the default, and not -P- 2- -P- doesn't actually work 3- ghostscript's scripts don't use -P- Fixing this will change the default behaviour, and may introduce regressions in software in the archive, and custom software. Since this is primarily a user-assisted attack, the risks of fixing this outweighs the advantages. Marking as ignored for affected releases.
Patch details
Package | Patch details |
---|---|
ghostscript |