CVE-2014-0466
published 2014-04-03CVE-2014-0466: The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute…
PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.34%
81.7th percentile
The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | a2ps | < a2ps 1:4.14-1.3 (bookworm) | a2ps 1:4.14-1.3 (bookworm) |
| gnu | a2ps | — | — |
| gnu | a2ps | >= 0 < 1:4.14-1.3 | 1:4.14-1.3 |
| gnu | a2ps | >= 0 < 1:4.14-1.3 | 1:4.14-1.3 |
| gnu | a2ps | >= 0 < 1:4.14-1.3 | 1:4.14-1.3 |
| gnu | a2ps | >= 0 < 1:4.14-1.3 | 1:4.14-1.3 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
a2ps: fixps does not invoke gs with -dSAFER
vendor_redhat·2014-03-28·CVSS 6.8
CVE-2014-0466 [MEDIUM] a2ps: fixps does not invoke gs with -dSAFER
a2ps: fixps does not invoke gs with -dSAFER
The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
Statement: This issue did not affect the versions of a2ps as shipped with Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: a2ps (Red Hat Enterprise Linux 5) - Will not fix
Package: a2ps (Red Hat Enterprise Linux 6) - Will not fix
Package: a2ps (Red Hat Enterprise Linux
Debian
CVE-2014-0466: a2ps - The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs,...
vendor_debian·2014·CVSS 6.8
CVE-2014-0466 [MEDIUM] CVE-2014-0466: a2ps - The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs,...
The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
Scope: local
bookworm: resolved (fixed in 1:4.14-1.3)
bullseye: resolved (fixed in 1:4.14-1.3)
forky: resolved (fixed in 1:4.14-1.3)
sid: resolved (fixed in 1:4.14-1.3)
trixie: resolved (fixed in 1:4.14-1.3)
GHSA
GHSA-5wf6-vx35-ff8x: The fixps script in a2ps 4
ghsa_unreviewed·2022-05-17
CVE-2014-0466 [MEDIUM] GHSA-5wf6-vx35-ff8x: The fixps script in a2ps 4
The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
OSV
CVE-2014-0466: The fixps script in a2ps 4
osv·2014-04-03·CVSS 6.8
CVE-2014-0466 [MEDIUM] CVE-2014-0466: The fixps script in a2ps 4
The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0466 a2ps: fixps does not invoke gs with -dSAFER
bugzilla·2014-03-31·CVSS 6.8
CVE-2014-0466 [MEDIUM] CVE-2014-0466 a2ps: fixps does not invoke gs with -dSAFER
CVE-2014-0466 a2ps: fixps does not invoke gs with -dSAFER
brian m. carlson reported that a2ps's fixps script does not invoke gs with the -dSAFER option. Running fixps on a malicious PostScript file could result in files being deleted or arbitrary commands being executed with the privileges of the user running fixps.
A possible patch from Debian is available from the Debian bug: https://bugs.debian.org/cgi-bin/bugreport.cgi?msg=12;filename=a2ps-4.14-1.3-nmu.diff;att=1;bug=742902
Discussion:
Created a2ps tracking bugs for this issue:
Affects: fedora-all [bug 1082411]
Affects: epel-6 [bug 1082412]
---
a2ps-4.14-23.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
---
a2ps-4.14-23.fc19 has been pushed to the
Bugzilla
CVE-2014-0466 a2ps: fixps does not invoke gs with -dSAFER [fedora-all]
bugzilla·2014-03-31·CVSS 6.8
CVE-2014-0466 [MEDIUM] CVE-2014-0466 a2ps: fixps does not invoke gs with -dSAFER [fedora-all]
CVE-2014-0466 a2ps: fixps does not invoke gs with -dSAFER [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mu
Bugzilla
CVE-2014-0466 a2ps: fixps does not invoke gs with -dSAFER [epel-6]
bugzilla·2014-03-31·CVSS 6.8
CVE-2014-0466 [MEDIUM] CVE-2014-0466 a2ps: fixps does not invoke gs with -dSAFER [epel-6]
CVE-2014-0466 a2ps: fixps does not invoke gs with -dSAFER [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for a2ps: see
http://lists.opensuse.org/opensuse-updates/2014-04/msg00021.htmlhttp://www.debian.org/security/2014/dsa-2892http://www.securityfocus.com/bid/66660https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742902https://security.gentoo.org/glsa/201701-67http://lists.opensuse.org/opensuse-updates/2014-04/msg00021.htmlhttp://www.debian.org/security/2014/dsa-2892http://www.securityfocus.com/bid/66660https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742902https://security.gentoo.org/glsa/201701-67
2014-04-03
Published