Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2015-8107
Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2001-1593
Disclosure Date: April 05, 2014 (last updated October 05, 2023)
The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.
0
Attacker Value
Unknown
CVE-2014-0466
Disclosure Date: April 03, 2014 (last updated October 05, 2023)
The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
0
Attacker Value
Unknown
CVE-2004-1170
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.
0
Attacker Value
Unknown
CVE-2004-1377
Disclosure Date: December 27, 2004 (last updated February 22, 2025)
The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
0