cbcvebase.
CVE-2014-0466
published 2014-04-03

CVE-2014-0466: The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute…

PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.34%
81.7th percentile
The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiana2ps< a2ps 1:4.14-1.3 (bookworm)a2ps 1:4.14-1.3 (bookworm)
gnua2ps
gnua2ps>= 0 < 1:4.14-1.31:4.14-1.3
gnua2ps>= 0 < 1:4.14-1.31:4.14-1.3
gnua2ps>= 0 < 1:4.14-1.31:4.14-1.3
gnua2ps>= 0 < 1:4.14-1.31:4.14-1.3

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.