First published: Tue Sep 18 2001(Updated: )
ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ghostscript | <=6.51 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1353 has a medium severity rating due to the potential for local users to exploit it.
To fix CVE-2001-1353, upgrade Ghostscript to version 6.51 or later.
CVE-2001-1353 allows local users to read and write arbitrary files as the 'lp' user, which can lead to unauthorized access and modification of sensitive files.
Ghostscript versions prior to 6.51 are affected by CVE-2001-1353.
No, CVE-2001-1353 is not exploitable remotely as it requires local access to the machine.