Boletines de Vulnerabilidades |
Ejecución de código con a2ps |
|
Clasificación de la vulnerabilidad |
|
Propiedad | Valor |
Nivel de Confianza | Oficial |
Impacto | Obtener acceso |
Dificultad | Avanzado |
Requerimientos del atacante | Acceso remoto con cuenta |
Información sobre el sistema |
|
Propiedad | Valor |
Fabricant afectat | GNU/Linux |
Software afectado |
GNU a2ps 4.13, 4.13b FreeBSD Mandrake Linux 9.2 Mandrake Linux 9.2/AMD64 Mandrake Linux 10.0 Mandrake Linux 10.0/AMD64 Mandrake Linux 10.1 Mandrake Linux 10.1/X86_64 Mandrake Linux Corporate Server 2.1 Mandrake Linux Corporate Server 2.1/X86_64 |
Descripción |
|
La apliación a2ps no valida correctamente los nombres de fichero. Esta circunstancia podría ser aprovechada por un atacante con cuenta en el sistema para, creando ficheros con nombres especiales dentro de determinados directorios en que la víctima ejecuta a2ps, ejecutar comandos con los privilegios de la víctima. |
|
Solución |
|
Aplique los mecanismos de actualización propios de su sistema, o bien descargue las fuentes del software y compílelas usted mismo. Actualización de Software GNU a2ps Página oficial http://www.gnu.org/software/a2ps/ FreeBSD Aplique el parche proporcionado por el fabricante http://www.freebsd.org/cgi/cvsweb.cgi/~checkout~/ports/print/a2ps-letter/files/patch-select.c?rev=1.1&content-type=text/plain Mandrake Linux Mandrake Linux 9.2 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/RPMS/a2ps-4.13b-5.1.92mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/RPMS/a2ps-devel-4.13b-5.1.92mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/RPMS/a2ps-static-devel-4.13b-5.1.92mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/SRPMS/a2ps-4.13b-5.1.92mdk.src.rpm Mandrake Linux 9.2/AMD64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/RPMS/a2ps-4.13b-5.1.92mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/RPMS/a2ps-devel-4.13b-5.1.92mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/RPMS/a2ps-static-devel-4.13b-5.1.92mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/SRPMS/a2ps-4.13b-5.1.92mdk.src.rpm Mandrake Linux 10.0 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/a2ps-4.13b-5.1.100mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/a2ps-devel-4.13b-5.1.100mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/a2ps-static-devel-4.13b-5.1.100mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/SRPMS/a2ps-4.13b-5.1.100mdk.src.rpm Mandrake Linux 10.0/AMD64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/a2ps-4.13b-5.1.100mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/a2ps-devel-4.13b-5.1.100mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/a2ps-static-devel-4.13b-5.1.100mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/SRPMS/a2ps-4.13b-5.1.100mdk.src.rpm Mandrake Linux 10.1 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/a2ps-4.13b-5.1.101mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/a2ps-devel-4.13b-5.1.101mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/a2ps-static-devel-4.13b-5.1.101mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/SRPMS/a2ps-4.13b-5.1.101mdk.src.rpm Mandrake Linux 10.1/X86_64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/a2ps-4.13b-5.1.101mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/a2ps-devel-4.13b-5.1.101mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/a2ps-static-devel-4.13b-5.1.101mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/SRPMS/a2ps-4.13b-5.1.101mdk.src.rpm Mandrake Linux Corporate Server 2.1 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/RPMS/a2ps-4.13-14.1.C21mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/RPMS/a2ps-devel-4.13-14.1.C21mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/RPMS/a2ps-static-devel-4.13-14.1.C21mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/SRPMS/a2ps-4.13-14.1.C21mdk.src.rpm Mandrake Linux Corporate Server 2.1/X86_64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/RPMS/a2ps-4.13-14.1.C21mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/RPMS/a2ps-devel-4.13-14.1.C21mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/RPMS/a2ps-static-devel-4.13-14.1.C21mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/SRPMS/a2ps-4.13-14.1.C21mdk.src.rpm Debian Linux Debian 3.0 "Woody" Fuentes http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1.dsc http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1.diff.gz http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b.orig.tar.gz Alpha http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_alpha.deb ARM http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_arm.deb Intel IA-32 http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_i386.deb Intel IA-64 http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_ia64.deb HPPA http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_hppa.deb Motorola 680x0 http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_m68k.deb Big endian MIPS http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_mips.deb Little endian MIPS http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_mipsel.deb PowerPC http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_powerpc.deb IBM S/390 http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_s390.deb Sun Sparc http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_sparc.deb |
|
Identificadores estándar |
|
Propiedad | Valor |
CVE | CAN-2004-1170 |
BID | 11025 |
Recursos adicionales |
|
SecuriTeam: a2ps Executing Shell Commands From File Name http://www.securiteam.com/unixfocus/5MP0N2KDPA.html Mandrakesoft Security Advisory MDKSA-2004:140 http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:140 Debian Security Advisory DSA-612 http://www.debian.org/security/2004/dsa-612 |
Histórico de versiones |
||
Versión | Comentario | Data |
1.0 | Aviso emitido | 2004-12-01 |
1.1 | Aviso emitido por Debian Linux (DSA 612-1) | 2004-12-21 |