First published: Fri Dec 10 2004(Updated: )
a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU a2ps | =4.13b | |
Sun Java Desktop System | =2003 | |
Sun Java Desktop System | =2.0 | |
GNU a2ps | =4.13 | |
SUSE Linux | =9.0 | |
SUSE Linux | =9.0 | |
SUSE Linux | =8.2 | |
SUSE Linux | =8 | |
SUSE Linux | =9.0 | |
SUSE Linux | =9.1 | |
SUSE Linux | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1170 is considered critical as it allows remote attackers to execute arbitrary commands.
To fix CVE-2004-1170, you should upgrade to a secure version of a2ps or apply the relevant patches provided by your software vendor.
CVE-2004-1170 affects GNU a2ps versions 4.13 and 4.13b, as well as specific versions of Sun Java Desktop System and SUSE Linux.
CVE-2004-1170 can facilitate remote code execution attacks, allowing an attacker to run commands on the vulnerable system.
While CVE-2004-1170 was identified in 2004, vulnerabilities like it can still pose risks if outdated software remains in use.