CVE

Id
4157  
CVE No.
CVE-2001-1353  
Status
Candidate  
Description
ghostscript before 6.51 allows local users to read and write arbitrary files as the "lp" user via the file operator, even with -dSAFER enabled.  
Phase
Modified (20050702)  
Votes
ACCEPT(4) Alderson, Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat | REVIEWING(1) Cox  
Comments
Christey> [See Mark Cox" email to me 20020617, subject "can-2001-1353"] | Frech> XF:ghostscript-dsafer-read-files(7412)