7.2

CVE-2010-2055

Exploit

Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.

Data is provided by the National Vulnerability Database (NVD)
ArtifexAfpl Ghostscript Version6.0
ArtifexAfpl Ghostscript Version6.01
ArtifexAfpl Ghostscript Version6.50
ArtifexAfpl Ghostscript Version7.00
ArtifexAfpl Ghostscript Version7.03
ArtifexAfpl Ghostscript Version7.04
ArtifexAfpl Ghostscript Version8.00
ArtifexAfpl Ghostscript Version8.11
ArtifexAfpl Ghostscript Version8.12
ArtifexAfpl Ghostscript Version8.13
ArtifexAfpl Ghostscript Version8.14
ArtifexAfpl Ghostscript Version8.50
ArtifexAfpl Ghostscript Version8.51
ArtifexAfpl Ghostscript Version8.52
ArtifexAfpl Ghostscript Version8.53
ArtifexAfpl Ghostscript Version8.54
ArtifexGhostscript Fonts Version6.0
ArtifexGhostscript Fonts Version8.11
ArtifexGpl Ghostscript Version <= 8.71
ArtifexGpl Ghostscript Version8.01
ArtifexGpl Ghostscript Version8.15
ArtifexGpl Ghostscript Version8.50
ArtifexGpl Ghostscript Version8.51
ArtifexGpl Ghostscript Version8.54
ArtifexGpl Ghostscript Version8.56
ArtifexGpl Ghostscript Version8.57
ArtifexGpl Ghostscript Version8.60
ArtifexGpl Ghostscript Version8.61
ArtifexGpl Ghostscript Version8.62
ArtifexGpl Ghostscript Version8.63
ArtifexGpl Ghostscript Version8.64
ArtifexGpl Ghostscript Version8.70
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.169
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C