PT-2002-1015 · Html2Ps · Html2Ps

Published

2002-11-10

·

Updated

2012-10-11

·

CVE-2002-1275

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions html2ps version 1.0
Description The issue concerns an unknown vulnerability in the html2ps HTML/PostScript converter. It allows remote attackers to execute arbitrary code via unsanitized input. Multiple vulnerabilities in the html2ps package may lead to breaches of confidentiality, integrity, and availability of protected information, and these vulnerabilities can be exploited remotely.
Recommendations For html2ps version 1.0, as a temporary workaround, consider sanitizing the input to prevent the execution of arbitrary code until a patch is available. Restrict access to the html2ps converter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02938
CVE-2002-1275
DSA-192

Affected Products

Html2Ps