Vulnerability Name:

CVE-2002-1275 (CCN-10526)

Assigned:2002-10-31
Published:2002-10-31
Updated:2012-10-11
Summary:Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanitized input."
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2002-1275

Source: DEBIAN
Type: Patch, Vendor Advisory
DSA-192

Source: DEBIAN
Type: DSA-192
html2ps -- arbitrary code execution

Source: XF
Type: Vendor Advisory
lprng-html2ps-command-execution(10526)

Source: CCN
Type: LPRng Web site
LPRng

Source: SUSE
Type: UNKNOWN
SuSE-SA:2002:040

Source: CCN
Type: OSVDB ID: 3813
IRIX html2ps Arbitrary Code Execution

Source: BID
Type: UNKNOWN
6079

Source: CCN
Type: BID-6079
LPRNG html2ps Remote Command Execution Vulnerability

Source: XF
Type: UNKNOWN
lprng-html2ps-command-execution(10526)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:html2ps_project:html2ps:1.0:b1:*:*:*:*:*:*
  • OR cpe:/a:html2ps_project:html2ps:1.0:b2:*:*:*:*:*:*
  • OR cpe:/a:html2ps_project:html2ps:1.0:b3:*:*:*:*:*:*
  • OR cpe:/a:html2ps_project:html2ps:1.0:b4:*:*:*:*:*:*
  • OR cpe:/a:html2ps_project:html2ps:1.0:b5:*:*:*:*:*:*
  • OR cpe:/a:html2ps_project:html2ps:1.0:b6:*:*:*:*:*:*
  • OR cpe:/a:html2ps_project:html2ps:1.0:b7:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:debian:debian_linux:2.2:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:7.2:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:7.3:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:8.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.debian:def:192
    V
    arbitrary code execution
    2002-11-08
    BACK
    html2ps_project html2ps 1.0 b1
    html2ps_project html2ps 1.0 b2
    html2ps_project html2ps 1.0 b3
    html2ps_project html2ps 1.0 b4
    html2ps_project html2ps 1.0 b5
    html2ps_project html2ps 1.0 b6
    html2ps_project html2ps 1.0 b7
    debian debian linux 2.2
    suse suse linux 7.0
    suse suse linux 7.1
    suse suse linux 7.2
    suse suse linux 7.3
    suse suse linux 8.0
    debian debian linux 3.0
    suse suse linux 8.1