CVE-2004-1377: Low severity GNU a2ps vulnerability
The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1377?
CVE-2004-1377 has been classified as a high-severity vulnerability due to its ability to allow local users to overwrite arbitrary files.
How do I fix CVE-2004-1377?
To fix CVE-2004-1377, upgrade to a2ps version 4.13 or later which addresses the symlink vulnerability.
Who is affected by CVE-2004-1377?
CVE-2004-1377 affects users of a2ps versions prior to 4.13, including specific versions of Turbolinux.
What is a symlink attack in the context of CVE-2004-1377?
A symlink attack in CVE-2004-1377 allows local users to create symbolic links to overwrite files that the vulnerable scripts attempt to write.
Are there any workarounds for CVE-2004-1377?
While the best solution is upgrading, a temporary workaround could include removing or disabling the use of vulnerable scripts during the risk period.