CVE-2000-1163: Medium severity Aladdin Enterprises Ghostscript vulnerability
ghostscript before 5.10-16 uses an empty LDRUNPATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2000-1163?
CVE-2000-1163 has a low severity rating, as it primarily affects local users with access to a vulnerable system.
How do I fix CVE-2000-1163?
To fix CVE-2000-1163, update Ghostscript to a version that does not use an empty LD_RUN_PATH environmental variable.
Which versions of Ghostscript are affected by CVE-2000-1163?
CVE-2000-1163 affects Ghostscript versions 4.3, 5.10.10, 5.10.15, 5.10cl, and 5.50.
Can remote users exploit CVE-2000-1163?
No, CVE-2000-1163 cannot be exploited by remote users as it requires local access to the system.
What type of attack does CVE-2000-1163 enable?
CVE-2000-1163 enables local users to execute commands as other users by using Trojan horse libraries.