CVE-2010-2055
Publication date 22 July 2010
Last updated 24 July 2024
Ubuntu priority
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.
Status
Package | Ubuntu Release | Status |
---|---|---|
ghostscript | 11.04 natty |
Not affected
|
10.10 maverick | Ignored | |
10.04 LTS lucid | Ignored | |
9.10 karmic | Ignored end of life | |
9.04 jaunty | Ignored end of life | |
8.04 LTS hardy | Ignored | |
6.06 LTS dapper | Not in release | |
gs-afpl | 11.04 natty | Not in release |
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
9.04 jaunty | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Ignored end of life | |
gs-esp | 11.04 natty | Not in release |
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
9.04 jaunty | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Ignored end of life | |
gs-gpl | 11.04 natty | Not in release |
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
9.04 jaunty | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Ignored end of life |
Notes
mdeslaur
There are three different issues here: 1- -P is the default, and not -P- 2- -P- doesn’t actually work 3- ghostscript’s scripts don’t use -P- Fixing this will change the default behaviour, and may introduce regressions in software in the archive, and custom software. Since this is primarily a user-assisted attack, the risks of fixing this outweighs the advantages. Marking as ignored for affected releases.
Patch details
Package | Patch details |
---|---|
ghostscript |