CVE-2015-8107
Published Apr 13, 2017Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.
Vendor/product archive
5 CVEs tagged to gnu / a2ps — 1 Critical, 1 High, 1 Medium, 2 Low, 0 Unrated.
Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.
The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary file…
The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands v…
a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.
The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.