CVE-2004-1170: Critical severity gnu a2ps vulnerability
Published Dec 10, 2004
·Updated
a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.
Affected Software
11 affected components
GNU a2ps=4.13b
Sun Java Desktop System=2003
Sun Java Desktop System=2.0
GNU a2ps=4.13
SUSE SuSE Linux=9.0
SUSE SuSE Linux=9.0
SUSE SuSE Linux=8.2
SUSE SuSE Linux=8
SUSE SuSE Linux=9.0
SUSE SuSE Linux=9.1
SUSE SuSE Linux=8.1
Remediation
Patch Available
Event History
Dec 10, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1170?
CVE-2004-1170 is considered critical as it allows remote attackers to execute arbitrary commands.
2
How do I fix CVE-2004-1170?
To fix CVE-2004-1170, you should upgrade to a secure version of a2ps or apply the relevant patches provided by your software vendor.
3
Which software is affected by CVE-2004-1170?
CVE-2004-1170 affects GNU a2ps versions 4.13 and 4.13b, as well as specific versions of Sun Java Desktop System and SUSE Linux.
4
What kind of attacks can CVE-2004-1170 facilitate?
CVE-2004-1170 can facilitate remote code execution attacks, allowing an attacker to run commands on the vulnerable system.
5
Is CVE-2004-1170 still relevant today?
While CVE-2004-1170 was identified in 2004, vulnerabilities like it can still pose risks if outdated software remains in use.