PSToText Arbitrary Code Execution Vulnerability
BID:14378
Info
PSToText Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 14378 |
| Class: | Design Error |
| CVE: |
CVE-2005-2536 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Max Vozeler <[email protected]> reported this issue. |
| Vulnerable: |
pstotext pstotext 1.9 pstotext pstotext 1.8 Gentoo Linux |
| Not Vulnerable: | |
Discussion
PSToText Arbitrary Code Execution Vulnerability
pstotext is susceptible to an arbitrary command execution vulnerability. This issue is due to a failure of the application to ensure that GhostScript is executed in a secure manner.
This issue allows attackers to create malicious PostScript files, that when parsed by the affected utility, allow arbitrary commands to be executed. This occurs in the context of the user running the affected utility.
pstotext is susceptible to an arbitrary command execution vulnerability. This issue is due to a failure of the application to ensure that GhostScript is executed in a secure manner.
This issue allows attackers to create malicious PostScript files, that when parsed by the affected utility, allow arbitrary commands to be executed. This occurs in the context of the user running the affected utility.
Exploit / POC
PSToText Arbitrary Code Execution Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
PSToText Arbitrary Code Execution Vulnerability
Solution:
Gentoo has released advisory GLSA 200507-29 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=app-text/pstotext-1.8g-r1"
Debian has released advisory DSA 792-1 to address this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
pstotext pstotext 1.8
pstotext pstotext 1.9
Solution:
Gentoo has released advisory GLSA 200507-29 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=app-text/pstotext-1.8g-r1"
Debian has released advisory DSA 792-1 to address this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
pstotext pstotext 1.8
-
Debian pstotext_1.8g-5woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g- 5woody1_alpha.deb -
Debian pstotext_1.8g-5woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g- 5woody1_arm.deb -
Debian pstotext_1.8g-5woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g- 5woody1_hppa.deb -
Debian pstotext_1.8g-5woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g- 5woody1_i386.deb -
Debian pstotext_1.8g-5woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g- 5woody1_ia64.deb -
Debian pstotext_1.8g-5woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g- 5woody1_m68k.deb -
Debian pstotext_1.8g-5woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g- 5woody1_mips.deb -
Debian pstotext_1.8g-5woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g- 5woody1_mipsel.deb -
Debian pstotext_1.8g-5woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g- 5woody1_powerpc.deb -
Debian pstotext_1.8g-5woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g- 5woody1_s390.deb -
Debian pstotext_1.8g-5woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g- 5woody1_sparc.deb
pstotext pstotext 1.9
-
Debian pstotext_1.9-1sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1 sarge1_alpha.deb -
Debian pstotext_1.9-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1 sarge1_amd64.deb -
Debian pstotext_1.9-1sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1 sarge1_arm.deb -
Debian pstotext_1.9-1sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1 sarge1_hppa.deb -
Debian pstotext_1.9-1sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1 sarge1_i386.deb -
Debian pstotext_1.9-1sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1 sarge1_ia64.deb -
Debian pstotext_1.9-1sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1 sarge1_m68k.deb -
Debian pstotext_1.9-1sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1 sarge1_mips.deb -
Debian pstotext_1.9-1sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1 sarge1_mipsel.deb -
Debian pstotext_1.9-1sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1 sarge1_powerpc.deb -
Debian pstotext_1.9-1sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1 sarge1_s390.deb -
Debian pstotext_1.9-1sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1 sarge1_sparc.deb
References
PSToText Arbitrary Code Execution Vulnerability
References:
References: