The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
A2ps | Gnu | 4.14 (including) | 4.14 (including) |
A2ps | Ubuntu | lucid | * |
A2ps | Ubuntu | precise | * |
A2ps | Ubuntu | quantal | * |
A2ps | Ubuntu | saucy | * |
A2ps | Ubuntu | upstream | * |