10
CVSSv2

CVE-2004-1170

Published: 10/01/2005 Updated: 19/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

a2ps 4.13 allows remote malicious users to execute arbitrary commands via shell metacharacters in the filename.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu a2ps 4.13

gnu a2ps 4.13b

sun java desktop system 2.0

sun java desktop system 2003

suse suse linux 9.0

suse suse linux 9.1

suse suse linux 8.1

suse suse linux 8.2

suse suse linux 8

Exploits

source: wwwsecurityfocuscom/bid/11025/info Reportedly GNU a2ps is affected by a filename command-execution vulnerability This issue is due to the application's failure to properly sanitize filenames An attacker might leverage this issue to execute arbitrary shell commands with the privileges of an unsuspecting user running the vulnerab ...