PT-2001-1069 · Tetex+1 · Tetex-Doc+9

Published

2001-08-22

·

Updated

2017-10-10

·

CVE-2001-1002

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Red Hat Linux versions 7.0 and earlier tetex-doc versions 1.0.6 through 1.0.7 tetex-fonts versions 1.0.6 through 1.0.7 tetex-afm versions 1.0.6 through 1.0.7 tetex-dvips versions 1.0.6 through 1.0.7 tetex-xdvi versions 1.0.6 through 1.0.7 tetex-latex versions 1.0.6 through 1.0.7 tetex-dvilj versions 1.0.6 through 1.0.7 tetex versions 1.0.6 through 1.0.7
Description The issue affects the default configuration of the DVI print filter (dvips) in Red Hat Linux, which does not run dvips in secure mode when executed by lpd. This could allow remote attackers to gain privileges by printing a DVI file that contains malicious commands. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For Red Hat Linux version 7.0 and earlier, consider updating the configuration to run dvips in secure mode. For tetex-doc versions 1.0.6 through 1.0.7, tetex-fonts versions 1.0.6 through 1.0.7, tetex-afm versions 1.0.6 through 1.0.7, tetex-dvips versions 1.0.6 through 1.0.7, tetex-xdvi versions 1.0.6 through 1.0.7, tetex-latex versions 1.0.6 through 1.0.7, tetex-dvilj versions 1.0.6 through 1.0.7, and tetex versions 1.0.6 through 1.0.7, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08226
BDU:2015-08227
BDU:2015-08228
BDU:2015-08229
BDU:2015-08230
BDU:2015-08231
BDU:2015-08232
BDU:2015-08233
BDU:2015-08234
BDU:2015-08235
BDU:2015-08236
BDU:2015-08237
BDU:2015-08238
BDU:2015-08239
BDU:2015-08240
BDU:2015-08241
CVE-2001-1002

Affected Products

Red Hat
Dvips
Tetex
Tetex-Afm
Tetex-Doc
Tetex-Dvilj
Tetex-Dvips
Tetex-Fonts
Tetex-Latex
Tetex-Xdvi