Vulnerability Name:

CVE-2014-0466 (CCN-92592)

Assigned:2013-12-19
Published:2014-03-28
Updated:2017-12-16
Summary:The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2014-0466

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2014:0499

Source: DEBIAN
Type: UNKNOWN
DSA-2892

Source: CCN
Type: GNU Web site
a2ps

Source: BID
Type: UNKNOWN
66660

Source: CCN
Type: BID-66660
GNU a2ps CVE-2014-0466 Arbitrary Command Execution Vulnerability

Source: CCN
Type: Debian Bug report logs - #742902
a2ps: CVE-2014-0466: does not invoke gs with -dSAFER

Source: CONFIRM
Type: UNKNOWN
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742902

Source: XF
Type: UNKNOWN
a2ps-cve20140466-command-exec(92592)

Source: GENTOO
Type: UNKNOWN
GLSA-201701-67

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnu:a2ps:4.14:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:gnu:a2ps:4.14:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20140466
    V
    CVE-2014-0466
    2022-06-30
    oval:org.opensuse.security:def:111917
    P
    a2ps-4.14-6.6 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:34005
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:33741
    P
    Security update for postgresql, postgresql13, postgresql14 (Important)
    2021-11-20
    oval:org.opensuse.security:def:55267
    P
    Security update for samba (Important)
    2021-11-16
    oval:org.opensuse.security:def:33040
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:32209
    P
    Security update for postgresql10 (Important)
    2021-10-20
    oval:org.opensuse.security:def:105485
    P
    a2ps-4.14-6.6 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:33001
    P
    Security update for qemu (Moderate)
    2021-09-09
    oval:org.opensuse.security:def:26121
    P
    Security update for ntfs-3g_ntfsprogs (Important)
    2021-09-07
    oval:org.opensuse.security:def:55945
    P
    Security update for libesmtp (Important)
    2021-09-02
    oval:org.opensuse.security:def:33956
    P
    Security update for libcares2 (Important)
    2021-08-16
    oval:org.opensuse.security:def:32153
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-07-27
    oval:org.opensuse.security:def:36077
    P
    a2ps-4.13-1326.37.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36368
    P
    a2ps-devel-4.13-1326.37.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42484
    P
    a2ps-4.13-1326.37.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:31629
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:26052
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:33898
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:30064
    P
    Security update for qemu (Important)
    2021-04-22
    oval:org.opensuse.security:def:29345
    P
    Security update for spamassassin (Important)
    2021-04-12
    oval:org.opensuse.security:def:30001
    P
    Security update for fwupdate (Important)
    2021-04-09
    oval:org.opensuse.security:def:34044
    P
    Security update for wavpack (Important)
    2021-03-24
    oval:org.opensuse.security:def:55864
    P
    Security update for glib2 (Important)
    2021-03-16
    oval:org.opensuse.security:def:26203
    P
    Security update for openldap2 (Important)
    2021-03-03
    oval:org.opensuse.security:def:26202
    P
    Security update for MozillaFirefox (Important)
    2021-03-01
    oval:org.opensuse.security:def:29476
    P
    Security update for perl-XML-Twig (Moderate)
    2021-03-01
    oval:org.opensuse.security:def:32258
    P
    Security update for screen (Important)
    2021-02-17
    oval:org.opensuse.security:def:30020
    P
    Security update for python (Important)
    2021-02-11
    oval:org.opensuse.security:def:55826
    P
    Security update for dnsmasq (Important)
    2021-01-19
    oval:org.opensuse.security:def:33653
    P
    Security update for dnsmasq (Important)
    2021-01-19
    oval:org.opensuse.security:def:29962
    P
    Security update for MozillaFirefox (Critical)
    2020-12-21
    oval:org.opensuse.security:def:25638
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25968
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26305
    P
    Security update for python-setuptools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27040
    P
    systemtap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25918
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26547
    P
    freeradius-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26693
    P
    evolution-data-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26253
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26457
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:26830
    P
    t1lib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26985
    P
    logrotate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27258
    P
    pam_ldap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27609
    P
    Security update for pidgin
    2020-12-01
    oval:org.opensuse.security:def:27901
    P
    Security update for xalan-j2
    2020-12-01
    oval:org.opensuse.security:def:28632
    P
    Security update for a2ps
    2020-12-01
    oval:org.opensuse.security:def:29274
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:29620
    P
    Security update for bluez (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30702
    P
    Security update for MozillaFirefox, mozilla-nss, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:54422
    P
    argyllcms on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54995
    P
    python-pyOpenSSL on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55660
    P
    Security update for giflib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31543
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:31761
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32319
    P
    Security update for ruby (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33365
    P
    Security update for openvpn-openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:34791
    P
    Security update for a2ps
    2020-12-01
    oval:org.opensuse.security:def:25702
    P
    Security update for libvpx (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26344
    P
    Security update for mbedtls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27075
    P
    a2ps on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25929
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26259
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26596
    P
    libpng12-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27331
    P
    xorg-x11-libXfixes-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26254
    P
    Security update for dia (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26538
    P
    e2fsprogs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26883
    P
    dhcp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27029
    P
    socat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27182
    P
    libexif on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27386
    P
    cyrus-imapd-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27760
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27915
    P
    Security update for xorg-x11-libs
    2020-12-01
    oval:org.opensuse.security:def:29705
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:30739
    P
    Security update for a2ps
    2020-12-01
    oval:org.opensuse.security:def:54444
    P
    cups-filters on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55101
    P
    eog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55752
    P
    Security update for gdk-pixbuf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57221
    P
    Security update for gpg2
    2020-12-01
    oval:org.opensuse.security:def:31544
    P
    Security update for Samba
    2020-12-01
    oval:org.opensuse.security:def:31853
    P
    Security update for coreutils (Important)
    2020-12-01
    oval:org.opensuse.security:def:32363
    P
    Security update for sudo (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33272
    P
    tcpdump on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33500
    P
    Security update for Mozilla
    2020-12-01
    oval:org.opensuse.security:def:34069
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25626
    P
    Security update for libqt5-qtbase (Important)
    2020-12-01
    oval:org.opensuse.security:def:25830
    P
    Security update for libimobiledevice, usbmuxd (Important)
    2020-12-01
    oval:org.opensuse.security:def:26358
    P
    Security update for Mozilla Thunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:25993
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26343
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:26635
    P
    quagga on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27366
    P
    a2ps-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26265
    P
    Security update for guile (Low)
    2020-12-01
    oval:org.opensuse.security:def:26595
    P
    libopenssl0_9_8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26932
    P
    krb5-doc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27667
    P
    Security update for rubygem-activesupport-3_2
    2020-12-01
    oval:org.opensuse.security:def:27183
    P
    libexiv2-4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27468
    P
    libopenssl-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27813
    P
    Security update for librsvg (Important)
    2020-12-01
    oval:org.opensuse.security:def:27959
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:29262
    P
    Security update for wget (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29858
    P
    Security update for Linux Kernel
    2020-12-01
    oval:org.opensuse.security:def:54584
    P
    libpcsclite1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57295
    P
    Security update for a2ps
    2020-12-01
    oval:org.opensuse.security:def:31555
    P
    Security update for sqlite3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31910
    P
    Security update for fuse (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33273
    P
    tftp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33596
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:34113
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25627
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25911
    P
    Security update for gstreamer-plugins-base (Low)
    2020-12-01
    oval:org.opensuse.security:def:26256
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26402
    P
    Security update for irssi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25917
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:26494
    P
    Security update for pdns-recursor (Important)
    2020-12-01
    oval:org.opensuse.security:def:26649
    P
    wireshark on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26329
    P
    Security update for znc (Low)
    2020-12-01
    oval:org.opensuse.security:def:26679
    P
    cron on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26971
    P
    libsndfile on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27702
    P
    Security update for a2ps
    2020-12-01
    oval:org.opensuse.security:def:27194
    P
    liblzo2-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27525
    P
    openldap2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27862
    P
    Security update for Python
    2020-12-01
    oval:org.opensuse.security:def:28597
    P
    Security update for Python
    2020-12-01
    oval:org.opensuse.security:def:29263
    P
    Security update for wpa_supplicant (Important)
    2020-12-01
    oval:org.opensuse.security:def:29563
    P
    Security update for OpenEXR (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29913
    P
    Security update for libcap
    2020-12-01
    oval:org.opensuse.security:def:54421
    P
    alsa on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54822
    P
    lhasa on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55552
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:31997
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:32297
    P
    Security update for procps (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33284
    P
    wget on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34751
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.mitre.oval:def:25285
    P
    SUSE-SU-2014:0581-1 -- Security update for a2ps
    2014-09-08
    oval:org.mitre.oval:def:24211
    P
    DSA-2892-1 a2ps - security update
    2014-07-21
    oval:com.ubuntu.precise:def:20140466000
    V
    CVE-2014-0466 on Ubuntu 12.04 LTS (precise) - medium.
    2014-04-03
    oval:com.ubuntu.trusty:def:20140466000
    V
    CVE-2014-0466 on Ubuntu 14.04 LTS (trusty) - medium.
    2014-04-03
    oval:org.opensuse.security:def:79929
    P
    Security update for a2ps
    2014-03-31
    BACK
    gnu a2ps 4.14
    gnu a2ps 4.14