First published: Fri Aug 05 2005(Updated: )
pstopnm in netpbm does not properly use the "-dSAFER" option when calling Ghostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3) PNM file, which allows external user-assisted attackers to execute arbitrary commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netpbm | =2.10.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2471 is considered a critical vulnerability due to the potential for arbitrary command execution.
To fix CVE-2005-2471, upgrade to a version of netpbm that does not have this vulnerability.
CVE-2005-2471 affects netpbm version 2.10.0.8.
CVE-2005-2471 requires user-assisted actions, making it more difficult for remote exploitation.
CVE-2005-2471 involves PostScript files being converted into PBM, PGM, or PNM file formats.