mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 06:55:56 +02:00
877 B
877 B
CVE-2010-2055
Description
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.
POC
Reference
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583183
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583316
Github
No PoCs found on GitHub currently.