search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Aladdin Ghostscript LD_RUN_PATH environment variable allows libraries to be loaded from current directory

Vulnerability Note VU#704976

Original Release Date: 2001-08-21 | Last Revised: 2001-08-22

Overview

Alladin Ghostscript, a previewer for postscript files, uses an insecure value for the LD_RUN_PATH environment variable. This allows attackers to supply malicious libraries to be loaded from the current directory.

Description

Alladin Ghostscript is a previewer for postscript files. In execution, it uses an insecure value for the LD_RUN_PATH enviroment variable, which specifies where to find run-time-loaded program libraries. Due to the insecure value, the libraries may be loaded from the current directory.

Impact

By substituting malicious code for functions called from program libraries, an attacker may execute arbitrary commands within the permissions of the user. This is particularly dangerous for the root account, where the malicious code may grant administrative privilege to the attacker.

Solution

Apply vendor patches; see the Systems Affected section below.

Vendor Information

704976
 

Caldera Affected

Notified:  November 22, 2000 Updated: July 02, 2001

Status

Affected

Vendor Statement

http://www.caldera.com/support/security/advisories/CSSA-2000-041.0.txt

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.

Conectiva Affected

Notified:  November 22, 2000 Updated: July 02, 2001

Status

Affected

Vendor Statement

http://www.linuxsecurity.com/advisories/other_advisory-919.html

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.

Debian Affected

Notified:  November 22, 2000 Updated: July 02, 2001

Status

Affected

Vendor Statement

http://www.debian.org/security/2000/20001123

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.

Immunix Affected

Notified:  November 22, 2000 Updated: July 02, 2001

Status

Affected

Vendor Statement

http://www.linuxsecurity.com/advisories/other_advisory-957.html

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.

MandrakeSoft Affected

Notified:  November 22, 2000 Updated: July 02, 2001

Status

Affected

Vendor Statement

http://www.linuxsecurity.com/advisories/mandrake_advisory-914.html

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.

RedHat Affected

Notified:  November 22, 2000 Updated: August 21, 2001

Status

Affected

Vendor Statement

http://www.redhat.com/support/errata/RHSA-2000-114.html

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Multiple linux vendors reported this vulnerability simultaneously.

This document was last modified by Tim Shimeall.

Other Information

CVE IDs: CVE-2000-1163
Severity Metric: 9.62
Date Public: 2000-11-22
Date First Published: 2001-08-21
Date Last Updated: 2001-08-22 15:26 UTC
Document Revision: 10

Sponsored by CISA.