MGASA-2014-0161

Source
https://advisories.mageia.org/MGASA-2014-0161.html
Import Source
https://advisories.mageia.org/MGASA-2014-0161.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0161
Related
Published
2014-04-04T10:58:23Z
Modified
2014-04-04T10:58:19Z
Summary
Updated a2ps packages fix CVE-2014-0466
Details

Updated a2ps packages fix security vulnerability:

Brian M. Carlson reported that a2ps's fixps script does not invoke gs with the -dSAFER option. Consequently executing fixps on a malicious PostScript file could result in files being deleted or arbitrary commands being executed with the privileges of the user running fixps (CVE-2014-0466).

References
Credits

Affected packages

Mageia:4 / a2ps

Package

Name
a2ps
Purl
pkg:rpm/mageia/a2ps?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.14-13.1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:3 / a2ps

Package

Name
a2ps
Purl
pkg:rpm/mageia/a2ps?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.14-12.2.mga3

Ecosystem specific

{
    "section": "core"
}