Description
The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files.
Product(s):
- Aladdin Enterprises Ghostscript 4.3.2
- Aladdin Enterprises Ghostscript 4.3
- Aladdin Enterprises Ghostscript 5.10.10
- Aladdin Enterprises Ghostscript 5.10.10 MDK
- Aladdin Enterprises Ghostscript 5.10.10_1
- Aladdin Enterprises Ghostscript 5.10.10_1 MDK
- Aladdin Enterprises Ghostscript 5.10.12cl
- Aladdin Enterprises Ghostscript 5.10.15
- Aladdin Enterprises Ghostscript 5.10.16
- Aladdin Enterprises Ghostscript 5.10cl
- Aladdin Enterprises Ghostscript 5.50.8
- Aladdin Enterprises Ghostscript 5.50.8_7
- Aladdin Enterprises Ghostscript 5.50
- Aladdin Enterprises Ghostscript 6.51
- Aladdin Enterprises Ghostscript 6.52
- Aladdin Enterprises Ghostscript 6.53
- Aladdin Enterprises Ghostscript 7.0.4
- Aladdin Enterprises Ghostscript 7.0.5
- Aladdin Enterprises Ghostscript 7.0.6
- Aladdin Enterprises Ghostscript 7.0.7
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2004-0967, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2004-0967 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.