Executive Summary

Informations
Name CVE-2010-4820 First vendor Publication 2014-10-26
Vendor Cve Last vendor Modification 2014-11-02

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 4.4 Attack Range Local
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 3.4 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different vulnerability than CVE-2010-2055.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4820

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-94 Failure to Control Generation of Code ('Code Injection')

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:20914
 
Oval ID: oval:org.mitre.oval:def:20914
Title: RHSA-2012:0095: ghostscript security update (Moderate)
Description: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Family: unix Class: patch
Reference(s): RHSA-2012:0095-01
CESA-2012:0095
CVE-2009-3743
CVE-2010-2055
CVE-2010-4054
CVE-2010-4820
Version: 55
Platform(s): Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
CentOS Linux 5
CentOS Linux 6
Product(s): ghostscript
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:23112
 
Oval ID: oval:org.mitre.oval:def:23112
Title: DEPRECATED: ELSA-2012:0095: ghostscript security update (Moderate)
Description: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Family: unix Class: patch
Reference(s): ELSA-2012:0095-01
CVE-2009-3743
CVE-2010-2055
CVE-2010-4054
CVE-2010-4820
Version: 22
Platform(s): Oracle Linux 5
Oracle Linux 6
Product(s): ghostscript
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:23156
 
Oval ID: oval:org.mitre.oval:def:23156
Title: ELSA-2012:0095: ghostscript security update (Moderate)
Description: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Family: unix Class: patch
Reference(s): ELSA-2012:0095-01
CVE-2009-3743
CVE-2010-2055
CVE-2010-4054
CVE-2010-4820
Version: 21
Platform(s): Oracle Linux 5
Oracle Linux 6
Product(s): ghostscript
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:27659
 
Oval ID: oval:org.mitre.oval:def:27659
Title: DEPRECATED: ELSA-2012-0095 -- ghostscript security update (moderate)
Description: [8.70-11:.6] - Applied upstream fix to last patch (CVE-2010-4054, bug #646086). [8.70-11:.5] - Applied patch to prevent null pointer dereference (CVE-2010-4054, bug #646086). [8.70-11:.4] - Don't ship patch backup files for CVE-2010-2055. [8.70-11:.3] - Applied patch to prevent integer underflow in TrueType bytecode interpreter (CVE-2009-3743, bug #627902). - Applied patch to avoid reading initialization files from CWD (CVE-2010-2055, bug #599564).
Family: unix Class: patch
Reference(s): ELSA-2012-0095
CVE-2009-3743
CVE-2010-2055
CVE-2010-4054
CVE-2010-4820
Version: 4
Platform(s): Oracle Linux 5
Oracle Linux 6
Product(s): ghostscript
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

OpenVAS Exploits

Date Description
2012-07-30 Name : CentOS Update for ghostscript CESA-2012:0095 centos5
File : nvt/gb_CESA-2012_0095_ghostscript_centos5.nasl
2012-07-30 Name : CentOS Update for ghostscript CESA-2012:0095 centos6
File : nvt/gb_CESA-2012_0095_ghostscript_centos6.nasl
2012-07-30 Name : CentOS Update for ghostscript CESA-2012:0096 centos4
File : nvt/gb_CESA-2012_0096_ghostscript_centos4.nasl
2012-02-03 Name : RedHat Update for ghostscript RHSA-2012:0095-01
File : nvt/gb_RHSA-2012_0095-01_ghostscript.nasl
2012-02-03 Name : RedHat Update for ghostscript RHSA-2012:0096-01
File : nvt/gb_RHSA-2012_0096-01_ghostscript.nasl

Nessus® Vulnerability Scanner

Date Description
2013-09-04 Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2012-42.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2012-0095.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2012-0096.nasl - Type : ACT_GATHER_INFO
2012-08-01 Name : The remote Scientific Linux host is missing one or more security updates.
File : sl_20120202_ghostscript_on_SL4_x.nasl - Type : ACT_GATHER_INFO
2012-08-01 Name : The remote Scientific Linux host is missing one or more security updates.
File : sl_20120202_ghostscript_on_SL5_x.nasl - Type : ACT_GATHER_INFO
2012-02-03 Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2012-0095.nasl - Type : ACT_GATHER_INFO
2012-02-03 Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2012-0096.nasl - Type : ACT_GATHER_INFO
2012-02-03 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2012-0095.nasl - Type : ACT_GATHER_INFO
2012-02-03 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2012-0096.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/51847
BUGTRAQ http://www.securityfocus.com/archive/1/511433
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=771853
MISC http://bugs.ghostscript.com/show_bug.cgi?id=691339
https://bugzilla.redhat.com/show_bug.cgi?id=599564
MLIST http://www.openwall.com/lists/oss-security/2012/01/04/7
REDHAT http://rhn.redhat.com/errata/RHSA-2012-0095.html
http://rhn.redhat.com/errata/RHSA-2012-0096.html

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
Date Informations
2021-05-04 12:13:15
  • Multiple Updates
2021-04-22 01:13:44
  • Multiple Updates
2020-05-23 00:27:19
  • Multiple Updates
2014-11-02 09:24:57
  • Multiple Updates
2014-10-28 00:22:09
  • Multiple Updates
2014-10-27 09:22:48
  • First insertion