cbcvebase.
CVE-2002-0836
published 2002-10-28

CVE-2002-0836: dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands…

PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.95%
94.1th percentile
dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.

Affected

12 ranges
VendorProductVersion rangeFixed in
hpsecure_os
mandrakesoftmandrake_linux
mandrakesoftmandrake_linux
mandrakesoftmandrake_linux
mandrakesoftmandrake_linux
mandrakesoftmandrake_linux
redhatlinux
redhatlinux
redhatlinux
redhatlinux
redhatlinux
redhatlinux

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.