CVE-2002-0363: High severity aladdin enterprises ghostscript vulnerability
Published May 29, 2002
·Updated
ghostscript before 6.53 allows attackers to execute arbitrary commands by using .locksafe or .setsafe to reset the current pagedevice.
Affected Software
1 affected component
Aladdin Enterprises Ghostscript<=6.53
Remediation
Event History
May 29, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0363?
CVE-2002-0363 is considered a critical vulnerability due to its ability to allow arbitrary command execution.
2
How do I fix CVE-2002-0363?
To fix CVE-2002-0363, upgrade to Ghostscript version 6.53 or later.
3
What versions of Ghostscript are affected by CVE-2002-0363?
Ghostscript versions before 6.53 are affected by CVE-2002-0363.
4
What type of attack is possible with CVE-2002-0363?
CVE-2002-0363 enables remote attackers to execute arbitrary commands on the system.
5
How can I determine if my system is vulnerable to CVE-2002-0363?
To determine if your system is vulnerable to CVE-2002-0363, check if you are running Ghostscript version prior to 6.53.