Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GNU a2ps 安全漏洞
Vulnerability Description
PostScript是一种适用于电子产业和桌面出版领域的页面描述语言和编程语言。a2ps是GNU计划开发的一款支持将任何类型的文件转换为PostScript文件的软件包。 a2ps 4.14版本中的fixps脚本存在安全漏洞,该漏洞源于当调用gs程序时,程序没有使用-dSAFER选项。攻击者可借助特制的PostScript文件利用该漏洞删除任意文件或执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A