CVE-2004-0967: High severity Aladdin Enterprises Ghostscript vulnerability
Published Oct 20, 2004
·Updated
The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files.
Affected Software
25 affected componentsFixes available
ubuntu/gs-common<0.3.9ubuntu1
0.3.9ubuntu1
ubuntu/gs-common<0.3.9ubuntu1
0.3.9ubuntu1
ubuntu/gs-common<0.3.9ubuntu1
0.3.9ubuntu1
debian/gs-common
debian/gs-gpl
Aladdin Enterprises Ghostscript=4.3
Aladdin Enterprises Ghostscript=4.3.2
Aladdin Enterprises Ghostscript=5.10.10
Aladdin Enterprises Ghostscript=5.10.10
Aladdin Enterprises Ghostscript=5.10.10_1
Aladdin Enterprises Ghostscript=5.10.10_1
Aladdin Enterprises Ghostscript=5.10.12cl
Aladdin Enterprises Ghostscript=5.10.15
Aladdin Enterprises Ghostscript=5.10.16
Aladdin Enterprises Ghostscript=5.10cl
Aladdin Enterprises Ghostscript=5.50
Aladdin Enterprises Ghostscript=5.50.8
Aladdin Enterprises Ghostscript=5.50.8_7
Aladdin Enterprises Ghostscript=6.51
Aladdin Enterprises Ghostscript=6.52
Aladdin Enterprises Ghostscript=6.53
Aladdin Enterprises Ghostscript=7.0.4
Aladdin Enterprises Ghostscript=7.0.5
Aladdin Enterprises Ghostscript=7.0.6
Aladdin Enterprises Ghostscript=7.0.7
Remediation
Patch Available
Event History
Oct 20, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Jun 13, 2024
Data Sourced
via Launchpad·04:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0967?
CVE-2004-0967 has a high severity rating as it allows local users to overwrite files using a symlink attack.
2
How do I fix CVE-2004-0967?
To fix CVE-2004-0967, you should upgrade to the gs-common package version 0.3.9ubuntu1 or later.
3
Which versions of Ghostscript are affected by CVE-2004-0967?
Affected versions of Ghostscript include 4.3, 5.x, and up to 7.0.7.
4
What operating systems are impacted by CVE-2004-0967?
CVE-2004-0967 affects Trustix Secure Linux 1.5 through 2.1 and other operating systems with vulnerable scripts.
5
What are the vulnerable scripts associated with CVE-2004-0967?
The vulnerable scripts are pj-gs.sh, ps2epsi, pv.sh, and sysvlp.sh.