2.6
CVE-2001-1353
- EPSS 0.32%
- Veröffentlicht 18.09.2001 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:56:06
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aladdin Enterprises ≫ Ghostscript Version <= 6.51
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.232 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.6 | 1.9 | 4.9 |
AV:L/AC:H/Au:N/C:P/I:P/A:N
|
http://archives.neohapsis.com/archives/hp/2001-q4/0069.html
http://marc.info/?l=lprng&m=100083210910857&w=2
http://rhn.redhat.com/errata/RHSA-2001-112.html
http://www.redhat.com/support/errata/RHSA-2001-138.html