Lucene search

K
freebsdFreeBSD8091FCEA-F35E-11D8-81B0-000347A4FA7D
HistoryAug 18, 2004 - 12:00 a.m.

a2ps -- insecure command line argument handling

2004-08-1800:00:00
vuxml.freebsd.org
17

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.034 Low

EPSS

Percentile

91.5%

Rudolf Polzer reports:

a2ps builds a command line for file() containing an
unescaped version of the file name, thus might call
external programs described by the file name. Running a
cronjob over a public writable directory a2ps-ing all
files in it - or simply typing “a2ps *.txt” in /tmp - is
therefore dangerous.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarcha2ps-a4< 4.13b_2UNKNOWN
FreeBSDanynoarcha2ps-letter< 4.13b_2UNKNOWN
FreeBSDanynoarcha2ps-letterdj< 4.13b_2UNKNOWN

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.034 Low

EPSS

Percentile

91.5%