cbcvebase.
CVE-2010-2055
published 2010-07-22

CVE-2010-2055: Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands…

PriorityP429high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.51%
40.2th percentile
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexafpl_ghostscript
artifexghostscript>= 0 < 8.71~dfsg2-6.18.71~dfsg2-6.1
artifexghostscript>= 0 < 8.71~dfsg2-6.18.71~dfsg2-6.1
artifexghostscript>= 0 < 8.71~dfsg2-6.18.71~dfsg2-6.1
artifexghostscript>= 0 < 8.71~dfsg2-6.18.71~dfsg2-6.1
artifexghostscript_fonts
artifexghostscript_fonts
artifexgpl_ghostscript<= 8.71
artifexgpl_ghostscript
artifexgpl_ghostscript

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.