CVE-2002-0836
published 2002-10-28CVE-2002-0836: dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.95%
94.1th percentile
dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | secure_os | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2002-10-14·CVSS 7.5
CVE-2002-0836 [HIGH] security flaw
security flaw
dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.
GHSA
GHSA-62pv-x8q7-86rc: dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary c
ghsa_unreviewed·2022-04-30
CVE-2002-0836 [HIGH] GHSA-62pv-x8q7-86rc: dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary c
dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.
No detection rules found.
No public exploits indexed.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000537http://marc.info/?l=bugtraq&m=103497852330838&w=2http://marc.info/?l=bugtraq&m=104005975415582&w=2http://www.debian.org/security/2002/dsa-207http://www.iss.net/security_center/static/10365.phphttp://www.kb.cert.org/vuls/id/169841http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-070.phphttp://www.redhat.com/support/errata/RHSA-2002-194.htmlhttp://www.redhat.com/support/errata/RHSA-2002-195.htmlhttp://www.securityfocus.com/advisories/4567http://www.securityfocus.com/bid/5978http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000537http://marc.info/?l=bugtraq&m=103497852330838&w=2http://marc.info/?l=bugtraq&m=104005975415582&w=2http://www.debian.org/security/2002/dsa-207http://www.iss.net/security_center/static/10365.phphttp://www.kb.cert.org/vuls/id/169841http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-070.phphttp://www.redhat.com/support/errata/RHSA-2002-194.htmlhttp://www.redhat.com/support/errata/RHSA-2002-195.htmlhttp://www.securityfocus.com/advisories/4567http://www.securityfocus.com/bid/5978
2002-10-28
Published