ALT-PU-2025-8883-1
Package a2ps updated to version 4.15.6-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
BDU:2015-02023
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
Modified: 2025-04-12
CVE-2001-1593
The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.
- http://pkgs.fedoraproject.org/cgit/a2ps.git/plain/a2ps-4.13-security.patch
- http://seclists.org/oss-sec/2014/q1/237
- http://seclists.org/oss-sec/2014/q1/253
- http://seclists.org/oss-sec/2014/q1/257
- http://www.debian.org/security/2014/dsa-2892
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737385
- https://bugzilla.redhat.com/show_bug.cgi?id=1060630
- http://pkgs.fedoraproject.org/cgit/a2ps.git/plain/a2ps-4.13-security.patch
- http://seclists.org/oss-sec/2014/q1/237
- http://seclists.org/oss-sec/2014/q1/253
- http://seclists.org/oss-sec/2014/q1/257
- http://www.debian.org/security/2014/dsa-2892
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737385
- https://bugzilla.redhat.com/show_bug.cgi?id=1060630
Modified: 2025-04-12
CVE-2014-0466
The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
- http://lists.opensuse.org/opensuse-updates/2014-04/msg00021.html
- http://www.debian.org/security/2014/dsa-2892
- http://www.securityfocus.com/bid/66660
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742902
- https://security.gentoo.org/glsa/201701-67
- http://lists.opensuse.org/opensuse-updates/2014-04/msg00021.html
- http://www.debian.org/security/2014/dsa-2892
- http://www.securityfocus.com/bid/66660
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742902
- https://security.gentoo.org/glsa/201701-67
Modified: 2025-04-20
CVE-2015-8107
Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.