Ghostscript 'gs_init.ps' With '-P-' Flag Search Path Local Privilege Escalation Vulnerability
BID:40467
Info
Ghostscript 'gs_init.ps' With '-P-' Flag Search Path Local Privilege Escalation Vulnerability
| Bugtraq ID: | 40467 |
| Class: | Design Error |
| CVE: |
CVE-2010-2055 |
| Remote: | No |
| Local: | Yes |
| Published: | May 31 2010 12:00AM |
| Updated: | Apr 13 2015 09:24PM |
| Credit: | Paul Szabo |
| Vulnerable: |
RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 4 Ghostscript Ghostscript 8.15.2 Ghostscript Ghostscript 8.0.1 Ghostscript Ghostscript 5.50 Ghostscript Ghostscript 8.64 Ghostscript Ghostscript 8.61 Ghostscript Ghostscript 8.60 Ghostscript Ghostscript 8.57 Ghostscript Ghostscript 8.56 Ghostscript Ghostscript 8.54 Ghostscript Ghostscript 8.15 Ghostscript Ghostscript 7.07 Ghostscript Ghostscript 7.05 Ghostscript Ghostscript 0 Gentoo Linux Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 |
| Not Vulnerable: | |
Discussion
Ghostscript 'gs_init.ps' With '-P-' Flag Search Path Local Privilege Escalation Vulnerability
Ghostscript is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with the privileges of the user running the application.
Ghostscript 8.64 is vulnerable; other versions may also be affected.
Ghostscript is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with the privileges of the user running the application.
Ghostscript 8.64 is vulnerable; other versions may also be affected.
Exploit / POC
Ghostscript 'gs_init.ps' With '-P-' Flag Search Path Local Privilege Escalation Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to run the application from the directory where a malicious file is stored.
An attacker can exploit this issue by enticing an unsuspecting user to run the application from the directory where a malicious file is stored.
Solution / Fix
Ghostscript 'gs_init.ps' With '-P-' Flag Search Path Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Ghostscript 'gs_init.ps' With '-P-' Flag Search Path Local Privilege Escalation Vulnerability
References:
References:
- Bug 691350 - gs_init.ps tried in current dir despite -P- (Paul Szabo)
- Ghostscript Homepage (Ghostscript)
- ghostscript security update (RHSA-2012-0095) (Avaya)
- Re: Ghostscript 8.64 executes random code at startup ([email protected])
- RE: Ghostscript 8.64 executes random code at startup ("Michael Wojcik"
)