GhostScript Insecure Temporary File Creation Vulnerability
BID:11285
Info
GhostScript Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 11285 |
| Class: | Design Error |
| CVE: |
CVE-2004-0967 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 30 2004 12:00AM |
| Updated: | May 10 2006 07:59PM |
| Credit: | Trustix security engineers are credited with the discovery of this vulnerability. |
| Vulnerable: |
SCO Unixware 7.1.4 SCO Open Server 6.0 SCO Open Server 5.0.7 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 3 Redhat Desktop 3.0 Aladdin Enterprises Ghostscript 7.0 7 Aladdin Enterprises Ghostscript 7.0 6 Aladdin Enterprises Ghostscript 7.0 5 Aladdin Enterprises Ghostscript 7.0 4 Aladdin Enterprises Ghostscript 6.53 Aladdin Enterprises Ghostscript 6.52 Aladdin Enterprises Ghostscript 6.51 Aladdin Enterprises Ghostscript 5.50.8 _7 Aladdin Enterprises Ghostscript 5.50.8 Aladdin Enterprises Ghostscript 5.50 Aladdin Enterprises Ghostscript 5.10.16 Aladdin Enterprises Ghostscript 5.10.15 Aladdin Enterprises Ghostscript 5.10.12 cl Aladdin Enterprises Ghostscript 5.10.10 mdk Aladdin Enterprises Ghostscript 5.10.10 -1 mdk Aladdin Enterprises Ghostscript 5.10.10 -1 Aladdin Enterprises Ghostscript 5.10.10 Aladdin Enterprises Ghostscript 5.10 cl Aladdin Enterprises Ghostscript 4.3.2 Aladdin Enterprises Ghostscript 4.3 |
| Not Vulnerable: | |
Discussion
GhostScript Insecure Temporary File Creation Vulnerability
Ghostscript creates temporary files in an insecure manor. This issue is likely due to a design error that causes the application to fail to verify the presence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly, this issue is unlikely to facilitate privilege escalation.
Ghostscript creates temporary files in an insecure manor. This issue is likely due to a design error that causes the application to fail to verify the presence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly, this issue is unlikely to facilitate privilege escalation.
Exploit / POC
GhostScript Insecure Temporary File Creation Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
GhostScript Insecure Temporary File Creation Vulnerability
Solution:
Please see the referenced vendor advisories for further information on obtaining and applying fixes.
Aladdin Enterprises Ghostscript 7.0 5
Aladdin Enterprises Ghostscript 7.0 7
Solution:
Please see the referenced vendor advisories for further information on obtaining and applying fixes.
Aladdin Enterprises Ghostscript 7.0 5
-
Trustix ghostscript-7.05.6-7tr.i586.rpm
Trustix Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix ghostscript-cups-7.05.6-7tr.i586.rpm
Trustix Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/
Aladdin Enterprises Ghostscript 7.0 7
-
Trustix ghostscript-7.07.1-4tr.i586.rpm
Trustix Secure Linux 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix ghostscript-cups-7.07.1-4tr.i586.rpm
Trustix Secure Linux 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/
References
GhostScript Insecure Temporary File Creation Vulnerability
References:
References:
- Ghostscript Homepage (Ghostscript)
- RHSA-2005:081-10 - ghostscript security update (RedHat)