rpm package
opensuse/a2ps&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/a2ps&distro=openSUSE%20Tumbleweed
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2001-1593 | — | < 4.15-1.1 | 4.15-1.1 | Apr 5, 2014 | The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file. | ||
| CVE-2014-0466 | — | < 4.14-6.6 | 4.14-6.6 | Apr 3, 2014 | The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file. | ||
| CVE-2004-1377 | — | < 4.14-6.6 | 4.14-6.6 | Dec 27, 2004 | The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files. |
- CVE-2001-1593Apr 5, 2014affected < 4.15-1.1fixed 4.15-1.1
The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.
- CVE-2014-0466Apr 3, 2014affected < 4.14-6.6fixed 4.14-6.6
The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
- CVE-2004-1377Dec 27, 2004affected < 4.14-6.6fixed 4.14-6.6
The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.