Vulnerability Bulletins |
Ejecución de código con a2ps |
|
Vulnerability classification |
|
Property | Value |
Confidence level | Oficial |
Impact | Obtener acceso |
Dificulty | Avanzado |
Required attacker level | Acceso remoto con cuenta |
System information |
|
Property | Value |
Affected manufacturer | GNU/Linux |
Affected software |
GNU a2ps 4.13, 4.13b FreeBSD Mandrake Linux 9.2 Mandrake Linux 9.2/AMD64 Mandrake Linux 10.0 Mandrake Linux 10.0/AMD64 Mandrake Linux 10.1 Mandrake Linux 10.1/X86_64 Mandrake Linux Corporate Server 2.1 Mandrake Linux Corporate Server 2.1/X86_64 |
Description |
|
La apliación a2ps no valida correctamente los nombres de fichero. Esta circunstancia podría ser aprovechada por un atacante con cuenta en el sistema para, creando ficheros con nombres especiales dentro de determinados directorios en que la víctima ejecuta a2ps, ejecutar comandos con los privilegios de la víctima. |
|
Solution |
|
Aplique los mecanismos de actualización propios de su sistema, o bien descargue las fuentes del software y compílelas usted mismo. Actualización de Software GNU a2ps Página oficial http://www.gnu.org/software/a2ps/ FreeBSD Aplique el parche proporcionado por el fabricante http://www.freebsd.org/cgi/cvsweb.cgi/~checkout~/ports/print/a2ps-letter/files/patch-select.c?rev=1.1&content-type=text/plain Mandrake Linux Mandrake Linux 9.2 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/RPMS/a2ps-4.13b-5.1.92mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/RPMS/a2ps-devel-4.13b-5.1.92mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/RPMS/a2ps-static-devel-4.13b-5.1.92mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/SRPMS/a2ps-4.13b-5.1.92mdk.src.rpm Mandrake Linux 9.2/AMD64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/RPMS/a2ps-4.13b-5.1.92mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/RPMS/a2ps-devel-4.13b-5.1.92mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/RPMS/a2ps-static-devel-4.13b-5.1.92mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/SRPMS/a2ps-4.13b-5.1.92mdk.src.rpm Mandrake Linux 10.0 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/a2ps-4.13b-5.1.100mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/a2ps-devel-4.13b-5.1.100mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/a2ps-static-devel-4.13b-5.1.100mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/SRPMS/a2ps-4.13b-5.1.100mdk.src.rpm Mandrake Linux 10.0/AMD64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/a2ps-4.13b-5.1.100mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/a2ps-devel-4.13b-5.1.100mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/a2ps-static-devel-4.13b-5.1.100mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/SRPMS/a2ps-4.13b-5.1.100mdk.src.rpm Mandrake Linux 10.1 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/a2ps-4.13b-5.1.101mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/a2ps-devel-4.13b-5.1.101mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/a2ps-static-devel-4.13b-5.1.101mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/SRPMS/a2ps-4.13b-5.1.101mdk.src.rpm Mandrake Linux 10.1/X86_64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/a2ps-4.13b-5.1.101mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/a2ps-devel-4.13b-5.1.101mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/a2ps-static-devel-4.13b-5.1.101mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/SRPMS/a2ps-4.13b-5.1.101mdk.src.rpm Mandrake Linux Corporate Server 2.1 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/RPMS/a2ps-4.13-14.1.C21mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/RPMS/a2ps-devel-4.13-14.1.C21mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/RPMS/a2ps-static-devel-4.13-14.1.C21mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/SRPMS/a2ps-4.13-14.1.C21mdk.src.rpm Mandrake Linux Corporate Server 2.1/X86_64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/RPMS/a2ps-4.13-14.1.C21mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/RPMS/a2ps-devel-4.13-14.1.C21mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/RPMS/a2ps-static-devel-4.13-14.1.C21mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/SRPMS/a2ps-4.13-14.1.C21mdk.src.rpm Debian Linux Debian 3.0 "Woody" Fuentes http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1.dsc http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1.diff.gz http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b.orig.tar.gz Alpha http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_alpha.deb ARM http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_arm.deb Intel IA-32 http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_i386.deb Intel IA-64 http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_ia64.deb HPPA http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_hppa.deb Motorola 680x0 http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_m68k.deb Big endian MIPS http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_mips.deb Little endian MIPS http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_mipsel.deb PowerPC http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_powerpc.deb IBM S/390 http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_s390.deb Sun Sparc http://security.debian.org/pool/updates/main/a/a2ps/a2ps_4.13b-16woody1_sparc.deb |
|
Standar resources |
|
Property | Value |
CVE | CAN-2004-1170 |
BID | 11025 |
Other resources |
|
SecuriTeam: a2ps Executing Shell Commands From File Name http://www.securiteam.com/unixfocus/5MP0N2KDPA.html Mandrakesoft Security Advisory MDKSA-2004:140 http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:140 Debian Security Advisory DSA-612 http://www.debian.org/security/2004/dsa-612 |
Version history |
||
Version | Comments | Date |
1.0 | Aviso emitido | 2004-12-01 |
1.1 | Aviso emitido por Debian Linux (DSA 612-1) | 2004-12-21 |