PT-2001-1003 · Gnu+3 · Gs+3
Brian M. Carlson
·
Published
2001-04-17
·
Updated
2024-06-15
·
CVE-2014-0466
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
a2ps versions 4.14
Description
The issue concerns multiple vulnerabilities in the a2ps package of the Debian GNU/Linux operating system, which can be exploited to compromise the confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be performed remotely. Specifically, the fixps script in a2ps does not use the -dSAFER option when executing gs, allowing context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
Recommendations
For a2ps version 4.14, consider disabling the fixps script until a patch is available to prevent potential exploitation. Restrict access to the gs execution to minimize the risk of arbitrary file deletion or command execution. Avoid using crafted PostScript files in the affected a2ps version until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Suse
A2Ps
Gs