CVE-2010-2055
published 2010-07-22CVE-2010-2055: Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands…
PriorityP429high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.51%
40.2th percentile
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | ghostscript | >= 0 < 8.71~dfsg2-6.1 | 8.71~dfsg2-6.1 |
| artifex | ghostscript | >= 0 < 8.71~dfsg2-6.1 | 8.71~dfsg2-6.1 |
| artifex | ghostscript | >= 0 < 8.71~dfsg2-6.1 | 8.71~dfsg2-6.1 |
| artifex | ghostscript | >= 0 < 8.71~dfsg2-6.1 | 8.71~dfsg2-6.1 |
| artifex | ghostscript_fonts | — | — |
| artifex | ghostscript_fonts | — | — |
| artifex | gpl_ghostscript | <= 8.71 | — |
| artifex | gpl_ghostscript | — | — |
| artifex | gpl_ghostscript | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ghostscript: gs_init.ps searched in current directory despite -P-
vendor_redhat·2010-05-26·CVSS 7.2
CVE-2010-2055 [HIGH] ghostscript: gs_init.ps searched in current directory despite -P-
ghostscript: gs_init.ps searched in current directory despite -P-
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.
Package: ghostscript (Red Hat Enterprise Linux 4) - Not affected
Red Hat
ghostscript: CWD included in the default library search path
vendor_redhat·2010-05-26·CVSS 7.2
CVE-2010-4820 [HIGH] ghostscript: CWD included in the default library search path
ghostscript: CWD included in the default library search path
Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different vulnerability than CVE-2010-2055.
Debian
CVE-2010-2055: ghostscript - Ghostscript 8.71 and earlier reads initialization files from the current working...
vendor_debian·2010·CVSS 7.2
CVE-2010-2055 [HIGH] CVE-2010-2055: ghostscript - Ghostscript 8.71 and earlier reads initialization files from the current working...
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.
Scope: local
bookworm: resolved (fixed in 8.71~dfsg2-6.1)
bullseye: resolved (fixed in 8.71~dfsg2-6.1)
forky: resolved (fixed in 8.71~dfsg2-6.1)
sid: resolved (fixed in 8.71~dfsg2-6.1)
trixie: resolved (fixed in 8.71~dfsg2-6.1)
Debian
CVE-2010-4820: ghostscript - Untrusted search path vulnerability in Ghostscript 8.62 allows local users to ex...
vendor_debian·2010·CVSS 7.2
CVE-2010-4820 [HIGH] CVE-2010-4820: ghostscript - Untrusted search path vulnerability in Ghostscript 8.62 allows local users to ex...
Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different vulnerability than CVE-2010-2055.
Scope: local
bookworm: resolved (fixed in 8.71~dfsg2-6.1)
bullseye: resolved (fixed in 8.71~dfsg2-6.1)
forky: resolved (fixed in 8.71~dfsg2-6.1)
sid: resolved (fixed in 8.71~dfsg2-6.1)
trixie: resolved (fixed in 8.71~dfsg2-6.1)
GHSA
GHSA-pxh5-rx4p-mm6h: Ghostscript 8
ghsa_unreviewed·2022-05-17·CVSS 4.4
CVE-2010-2055 [MEDIUM] GHSA-pxh5-rx4p-mm6h: Ghostscript 8
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.
GHSA
GHSA-37q2-9vp4-q6f4: Untrusted search path vulnerability in Ghostscript 8
ghsa_unreviewed·2022-05-17·CVSS 7.2
CVE-2010-4820 [HIGH] CWE-94 GHSA-37q2-9vp4-q6f4: Untrusted search path vulnerability in Ghostscript 8
Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different vulnerability than CVE-2010-2055.
OSV
CVE-2010-4820: Untrusted search path vulnerability in Ghostscript 8
osv·2014-10-27·CVSS 7.2
CVE-2010-4820 [HIGH] CVE-2010-4820: Untrusted search path vulnerability in Ghostscript 8
Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different vulnerability than CVE-2010-2055.
OSV
CVE-2010-2055: Ghostscript 8
osv·2010-07-22·CVSS 7.2
CVE-2010-2055 [HIGH] CVE-2010-2055: Ghostscript 8
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.
No detection rules found.
No public exploits indexed.
Bugzilla
ghostcript (various many shell scripts): CWD included in the default script search path
bugzilla·2013-01-07·CVSS 7.2
CVE-2010-2055 [HIGH] ghostcript (various many shell scripts): CWD included in the default script search path
ghostcript (various many shell scripts): CWD included in the default script search path
Originally, Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2055 to the following Ghostscript vulnerability:
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2055
[2] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2055
--
later a CVE identifier of CVE-2010-4820 was assigned to the insecure gs initialization issue.
References:
[3] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4820
[4] https://bugzil
Bugzilla
CVE-2010-4820 ghostscript: CWD included in the default library search path
bugzilla·2012-01-05·CVSS 7.2
CVE-2010-4820 [HIGH] CVE-2010-4820 ghostscript: CWD included in the default library search path
CVE-2010-4820 ghostscript: CWD included in the default library search path
Ghostscript included the current working directory in its library search path by default. If a user ran Ghostscript without the "-P-" option in an attacker-controlled directory containing a specially-crafted PostScript library file, it could cause Ghostscript to execute arbitrary PostScript code. With this update, Ghostscript no longer searches the current working directory for library files by default. (CVE-2010-4820)
Note: The fix for CVE-2010-4820 could possibly break existing configurations. To use the previous, vulnerable behavior, run Ghostscript with the "-P" option (to always search the current working directory first).
Discussion:
This issue was originally tracked with CVE-2010-2055 via bug #599564. It
Bugzilla
CVE-2010-2055 CVE-2009-3743 ghostscript various flaws [fedora-all]
bugzilla·2011-11-22·CVSS 9.3
CVE-2010-2055 [CRITICAL] CVE-2010-2055 CVE-2009-3743 ghostscript various flaws [fedora-all]
CVE-2010-2055 CVE-2009-3743 ghostscript various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=599
Bugzilla
CVE-2010-2055 ghostscript: gs_init.ps searched in current directory despite -P-
bugzilla·2010-06-03·CVSS 7.2
CVE-2010-2055 [HIGH] CVE-2010-2055 ghostscript: gs_init.ps searched in current directory despite -P-
CVE-2010-2055 ghostscript: gs_init.ps searched in current directory despite -P-
Security flaws were found in the way gs handled its initialization:
1, library search path include '.' (current working directory) by default,
causing ghostscript to search '.' for initialization and library postscript
files
2, explicit use of "-P-" command line option, did not prevent ghostscript from
executing PostScript commands, contained within "gs_init.ps" file.
A local attacker could use this flaw to execute arbitrary PostScript commands, if the victim was tricked into opening a PostScript file in the directory writeable by the attacker
References:
[1] http://bugs.ghostscript.com/show_bug.cgi?id=691339
[2] http://bugs.ghostscript.com/show_bug.cgi?id=691350
[3] http://www.securityfocus.com/archive/1/51
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583183http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583316http://bugs.ghostscript.com/show_bug.cgi?id=691339http://bugs.ghostscript.com/show_bug.cgi?id=691350http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043913.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/043948.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://savannah.gnu.org/forum/forum.php?forum_id=6368http://secunia.com/advisories/40452http://secunia.com/advisories/40475http://secunia.com/advisories/40532http://security.gentoo.org/glsa/glsa-201412-17.xmlhttp://www.osvdb.org/66247http://www.securityfocus.com/archive/1/511433http://www.securityfocus.com/archive/1/511472http://www.securityfocus.com/archive/1/511474http://www.securityfocus.com/archive/1/511476http://www.vupen.com/english/advisories/2010/1757https://bugzilla.novell.com/show_bug.cgi?id=608071https://bugzilla.redhat.com/show_bug.cgi?id=599564https://rhn.redhat.com/errata/RHSA-2012-0095.htmlhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583183http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583316http://bugs.ghostscript.com/show_bug.cgi?id=691339http://bugs.ghostscript.com/show_bug.cgi?id=691350http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043913.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/043948.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://savannah.gnu.org/forum/forum.php?forum_id=6368http://secunia.com/advisories/40452http://secunia.com/advisories/40475http://secunia.com/advisories/40532http://security.gentoo.org/glsa/glsa-201412-17.xmlhttp://www.osvdb.org/66247http://www.securityfocus.com/archive/1/511433http://www.securityfocus.com/archive/1/511472http://www.securityfocus.com/archive/1/511474http://www.securityfocus.com/archive/1/511476http://www.vupen.com/english/advisories/2010/1757https://bugzilla.novell.com/show_bug.cgi?id=608071https://bugzilla.redhat.com/show_bug.cgi?id=599564https://rhn.redhat.com/errata/RHSA-2012-0095.html
2010-07-22
Published