CVE-2010-4820
EPSS 0.11%
Description
Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different vulnerability than CVE-2010-2055.
How to fix CVE-2010-4820
To remediate CVE-2010-4820, upgrade the affected package to a fixed version below.
- Debian/ghostscript—upgrade to 8.71~dfsg2-6.1 or later
Is CVE-2010-4820 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 8.71~dfsg2-6.1