Gnu A2Ps vulnerabilities

5 known vulnerabilities affecting gnu/a2ps.

Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1LOW2

Vulnerabilities

Page 1 of 1
CVE-2015-8107HIGHCVSS 7.8v4.142017-04-13
CVE-2015-8107 [HIGH] CWE-134 CVE-2015-8107: Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code. Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.
nvd
CVE-2001-1593LOWCVSS 2.1≤ 4.14v4.10.3+4 more2014-04-05
CVE-2001-1593 [LOW] CWE-59 CVE-2001-1593: The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user fun The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.
nvd
CVE-2014-0466MEDIUMCVSS 6.8v4.142014-04-03
CVE-2014-0466 [MEDIUM] CVE-2014-0466: The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows contex The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
nvd
CVE-2004-1170CRITICALCVSS 10.0PoCv4.13v4.13b2005-01-10
CVE-2004-1170 [CRITICAL] CVE-2004-1170: a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the file a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.
nvd
CVE-2004-1377LOWCVSS 2.1v4.13v4.13b2004-12-27
CVE-2004-1377 [LOW] CVE-2004-1377: The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow lo The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
nvd