ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.
References
Configurations
History
20 Nov 2024, 23:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/hp/2001-q4/0069.html - | |
References | () http://marc.info/?l=lprng&m=100083210910857&w=2 - | |
References | () http://rhn.redhat.com/errata/RHSA-2001-112.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2001-138.html - Patch, Vendor Advisory |
Information
Published : 2001-09-18 04:00
Updated : 2024-11-20 23:37
NVD link : CVE-2001-1353
Mitre link : CVE-2001-1353
CVE.ORG link : CVE-2001-1353
JSON object : View
Products Affected
aladdin_enterprises
- ghostscript
CWE