cbcvebase.
CVE-2004-1170
published 2005-01-10

CVE-2004-1170: a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.

critical10CVSS 3.1
AVNACLAuNCCICAC
EXPLOIT
a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiana2ps< a2ps 1:4.13b-4.2 (bookworm)a2ps 1:4.13b-4.2 (bookworm)
gnua2ps
gnua2ps
gnua2ps>= 0 < 1:4.13b-4.21:4.13b-4.2
gnua2ps>= 0 < 1:4.13b-4.21:4.13b-4.2
gnua2ps>= 0 < 1:4.13b-4.21:4.13b-4.2
gnua2ps>= 0 < 1:4.13b-4.21:4.13b-4.2
msrcmicrosoft_forefront_endpoint_protection_2010
msrcmicrosoft_security_essentials
msrcmicrosoft_system_center_2012_endpoint_protection
msrcmicrosoft_system_center_2012_r2_endpoint_protection
msrcmicrosoft_system_center_endpoint_protection
msrcwindows_defender
sunjava_desktop_system
sunjava_desktop_system
susesuse_linux
susesuse_linux
susesuse_linux
susesuse_linux
susesuse_linux

CVSS provenance

nvd10.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL