Description
ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2000-1148 | ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T05:45:37.334Z
Reserved: 2000-12-14T00:00:00.000Z
Link: CVE-2000-1163
No data.
Status : Modified
Published: 2001-01-09T05:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2000-1163
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD