GNU a2ps CVE-2014-0466 Arbitrary Command Execution Vulnerability
BID:66660
Info
GNU a2ps CVE-2014-0466 Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 66660 |
| Class: | Unknown |
| CVE: |
CVE-2014-0466 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2014 12:00AM |
| Updated: | Feb 02 2017 01:03AM |
| Credit: | Brian M. Carlson |
| Vulnerable: |
Mandriva Business Server 1 X86 64 Mandriva Business Server 1 GNU a2ps 4.14 Gentoo Linux |
| Not Vulnerable: | |
Discussion
GNU a2ps CVE-2014-0466 Arbitrary Command Execution Vulnerability
GNU a2ps is prone to a remote arbitrary command-execution vulnerability because it fails to sanitize user-supplied input.
An attacker can exploit this issue to delete arbitrary files or execute arbitrary commands with the privileges of the user running 'fixps' script.
GNU a2ps is prone to a remote arbitrary command-execution vulnerability because it fails to sanitize user-supplied input.
An attacker can exploit this issue to delete arbitrary files or execute arbitrary commands with the privileges of the user running 'fixps' script.
Exploit / POC
GNU a2ps CVE-2014-0466 Arbitrary Command Execution Vulnerability
Attacker can exploit this issue using readily available tools.
Attacker can exploit this issue using readily available tools.
Solution / Fix
GNU a2ps CVE-2014-0466 Arbitrary Command Execution Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Mandriva Business Server 1 X86 64
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Mandriva Business Server 1 X86 64
-
Mandriva a2ps-4.14-13.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva a2ps-devel-4.14-13.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva a2ps-static-devel-4.14-13.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
GNU a2ps CVE-2014-0466 Arbitrary Command Execution Vulnerability
References:
References:
- a2ps Home Page (GNU)
- Bug 1082410 - (CVE-2014-0466) CVE-2014-0466 a2ps: fixps does not invoke gs with (Red Hat Bugzilla)
- Debian Bug report logs - #742902 a2ps: CVE-2014-0466: does not invoke gs with -d (Brian M. Carlson)