Vulnerability CVE-2001-1353


Published: 2001-09-18   Modified: 2012-02-12

Description:
ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.

CVSS2 => (AV:L/AC:H/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.6/10
4.9/10
1.9/10
Exploit range
Attack complexity
Authentication
Local
High
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
Aladdin enterprises -> Ghostscript 

 References:
http://archives.neohapsis.com/archives/hp/2001-q4/0069.html
http://marc.info/?l=lprng&m=100083210910857&w=2
http://rhn.redhat.com/errata/RHSA-2001-112.html
http://www.redhat.com/support/errata/RHSA-2001-138.html

Copyright 2024, cxsecurity.com

 

Back to Top