Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different vulnerability than CVE-2010-2055.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade ghostscript-gtkUpgrade ghostscriptUpgrade ghostscript-develUpgrade ghostscript-doc | Dec 1, 2016 | Oct 26, 2014 |
| Debian | — | Upgrade ghostscript | Jul 30, 2024 | Oct 27, 2014 |
| Oracle_linux | — | Upgrade ghostscript-develUpgrade ghostscript-gtkUpgrade ghostscriptUpgrade ghostscript-doc | Oct 16, 2024 | Oct 27, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub