PT-2001-1003 · Gnu+3 · Gs+3

Brian M. Carlson

·

Published

2001-04-17

·

Updated

2024-06-15

·

CVE-2014-0466

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions a2ps versions 4.14
Description The issue concerns multiple vulnerabilities in the a2ps package of the Debian GNU/Linux operating system, which can be exploited to compromise the confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be performed remotely. Specifically, the fixps script in a2ps does not use the -dSAFER option when executing gs, allowing context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
Recommendations For a2ps version 4.14, consider disabling the fixps script until a patch is available to prevent potential exploitation. Restrict access to the gs execution to minimize the risk of arbitrary file deletion or command execution. Avoid using crafted PostScript files in the affected a2ps version until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2020-3532
ALT-PU-2020-3547
ALT-PU-2022-1918
BDU:2015-02023
CVE-2014-0466
DSA-2892-1
MGASA-2014-0161
OPENSUSE-SU-2024:10086-1
SUSE-SU-2014_0581-1

Affected Products

Alt Linux
Suse
A2Ps
Gs