CVE-1999-0155: High severity Aladdin Enterprises Ghostscript vulnerability
The ghostscript command with the -dSAFER option allows remote attackers to execute commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Do not run the ghostscript command with the -dSAFER option; avoid invoking Ghostscript with -dSAFER because it allows remote attackers to execute commands.
Ghostscript -dSAFER = do not use / disable
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0155?
CVE-1999-0155 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-1999-0155?
To fix CVE-1999-0155, update to a patched version of Ghostscript that addresses this vulnerability.
What versions of Ghostscript are affected by CVE-1999-0155?
CVE-1999-0155 affects Ghostscript versions 2.6 and 3.22.
What security implications does CVE-1999-0155 have for users?
CVE-1999-0155 can allow remote attackers to execute arbitrary commands, posing significant security risks.
Is CVE-1999-0155 still relevant today?
Despite its age, CVE-1999-0155 is relevant as legacy systems using affected versions may still exist and be exploitable.