CVE-2014-0466: Medium severity GNU a2ps vulnerability
The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/a2psto a version that resolves this vulnerability.Fixed in 1:4.14-1.3Fixed in 1:4.14-1.1+deb7u1Fixed in 1:4.14-1.1+deb6u1 - Upgrade
Upgrade
debian/a2psto a version that resolves this vulnerability.Fixed in 1:4.14-7Fixed in 1:4.14-8Fixed in 1:4.15.6-1 - Upgrade
Upgrade
a2psto a version that resolves this vulnerability.Fixed in 4.14
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0466?
CVE-2014-0466 is considered to have medium severity due to the potential for file deletion and arbitrary command execution.
How do I fix CVE-2014-0466?
To fix CVE-2014-0466, update to a patched version of a2ps, specifically versions 1:4.14-1.3 or later.
What software is affected by CVE-2014-0466?
The vulnerability CVE-2014-0466 affects the GNU a2ps version 4.14.
Can CVE-2014-0466 be exploited remotely?
Yes, CVE-2014-0466 can potentially be exploited remotely through crafted PostScript files.
What is the potential impact of CVE-2014-0466?
The potential impact of CVE-2014-0466 includes unauthorized deletion of files and execution of arbitrary commands.