GNU a2ps Arbitrary Command Execution Vulnerability (CVE-2014-0466)
Release date:
Updated on:
Affected Systems:
GNU a2ps 4.14
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66660
CVE (CAN) ID: CVE-2014-0466
GNU a2ps is a filter that converts files to PostScript.
Fixps scripts in a2ps 4.14 do not use the-dSAFER option when running gs, which allows an attacker with independent context to execute arbitrary commands through specially crafted PostScript files.
<* Source: Brian M. Carlson
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
GNU
---
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.gnu.org/software/a2ps/
Reference: https://bugs.debian.org/cgi-bin/bugreport.cgi? Bug = 742902