PT-2005-3376 · Netpbm+2 · Netpbm+2

Max Vozeler

·

Publicado

2005-08-05

·

Atualizado

2017-10-11

·

CVE-2005-2471

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions netpbm (affected versions not specified)
Description The issue concerns the pstopnm function in netpbm, which fails to properly utilize the "-dSAFER" option when invoking Ghostscript for converting PostScript files into PBM, PGM, or PNM files. This oversight enables external attackers, with user assistance, to execute arbitrary commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2471
DSA-1021-1
RHSA-2005:743
RHSA-2005_743

Produtos afetados

Ghostscript
Red Hat
Netpbm