lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20100522093856.12938.qmail@securityfocus.com> Date: 22 May 2010 09:38:56 -0000 From: ne01026@...gny.2a.pl To: bugtraq@...urityfocus.com Subject: Ghostscript 8.64 executes random code at startup Ghostscript_8.64 on openSuSE_11.2 executes all files matching ./Encoding/* on startup. This search is relative to the current directory so it is easy to poison Ghostscript and cause it to execute arbitrary PostScript code without user action or knowledge. Details: <URL:https://bugzilla.novell.com/show_bug.cgi?id=608071>