CVE-2010-4820
Publication date 27 October 2014
Last updated 24 July 2024
Ubuntu priority
Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different vulnerability than CVE-2010-2055.
Status
Package | Ubuntu Release | Status |
---|---|---|
ghostscript | ||
gs-afpl | ||
gs-esp | ||
gs-gpl | ||
Notes
mdeslaur
This is related to CVE-2010-2055 Fixing this will change the default behaviour, and may introduce regressions in software in the archive, and custom software. Since this is primarily a user-assisted attack, the risks of fixing this outweighs the advantages. Marking as ignored for affected releases.
Patch details
Package | Patch details |
---|---|
ghostscript |