Bug 871097 (CVE-2014-0466) - VUL-0: CVE-2014-0466: a2ps: fixps does not use -dSAFER
Summary: VUL-0: CVE-2014-0466: a2ps: fixps does not use -dSAFER
Status: RESOLVED FIXED
Alias: CVE-2014-0466
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2014-04-14
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/97466/
Whiteboard: maint:released:sles9-sp3-teradata:56...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-03-31 07:37 UTC by Marcus Meissner
Modified: 2014-05-02 15:56 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2014-03-31 07:37:47 UTC
via rh bugzilla

Brian M Carlson reported that a2ps's fixps script does not invoke gs with the -dSAFER option. Running fixps on a malicious PostScript file could result in files being deleted or arbitrary commands being executed with the privileges of the user running fixps.

A possible patch from Debian is available from the Debian bug: https://bugs.debian.org/cgi-bin/bugreport.cgi?msg=12;filename=a2ps-4.14-1.3-nmu.diff;att=1;bug=742902
https://bugzilla.redhat.com/show_bug.cgi?id=1082410
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0466
Comment 1 Bernhard Wiedemann 2014-03-31 09:00:19 UTC
This is an autogenerated message for OBS integration:
This bug (871097) was mentioned in
https://build.opensuse.org/request/show/228269 Factory / a2ps
Comment 3 Bernhard Wiedemann 2014-03-31 11:00:23 UTC
This is an autogenerated message for OBS integration:
This bug (871097) was mentioned in
https://build.opensuse.org/request/show/228288 13.1 / a2ps
https://build.opensuse.org/request/show/228297 12.3 / a2ps
Comment 4 Swamp Workflow Management 2014-03-31 12:42:34 UTC
The SWAMPID for this issue is 56836.
This issue was rated as moderate.
Please submit fixed packages until 2014-04-14.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 5 SMASH SMASH 2014-03-31 12:45:15 UTC
Affected packages:

SLE-9-SP3-TERADATA: a2ps
SLE-10-SP3-TERADATA: a2ps
SLE-11-SP1: a2ps
SLE-11-SP3: a2ps
Comment 7 Dr. Werner Fink 2014-03-31 12:57:41 UTC
(In reply to comment #5)


  SLE-9-SP3-TERADATA: a2ps
  SLE-10-SP3-TERADATA: a2ps

an isc se a2ps does not show TERADATA
Comment 13 Swamp Workflow Management 2014-03-31 22:00:14 UTC
bugbot adjusting priority
Comment 14 Swamp Workflow Management 2014-04-09 16:05:04 UTC
openSUSE-SU-2014:0499-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 871097
CVE References: CVE-2014-0466
Sources used:
openSUSE 13.1 (src):    a2ps-4.13-1356.4.1
openSUSE 12.3 (src):    a2ps-4.13-1353.4.1
Comment 15 Swamp Workflow Management 2014-04-29 12:04:23 UTC
Update released for: a2ps, a2ps-debuginfo, a2ps-debugsource, a2ps-devel
Products:
SLE-DEBUGINFO 11-SP1-TERADATA (x86_64)
SLE-SERVER 11-SP1-TERADATA (x86_64)
Comment 16 Swamp Workflow Management 2014-04-29 12:05:14 UTC
Update released for: a2ps
Products:
SLE-SERVER 10-SP3-TERADATA (x86_64)
Comment 17 Swamp Workflow Management 2014-04-29 12:05:34 UTC
Update released for: a2ps
Products:
SUSE-CORE 9-SP3-TERADATA (x86_64)
Comment 18 Swamp Workflow Management 2014-04-29 17:51:58 UTC
Update released for: a2ps, a2ps-debuginfo, a2ps-debugsource, a2ps-devel
Products:
SLE-DEBUGINFO 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLE-DESKTOP 11-SP3 (i386, x86_64)
SLE-SDK 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP3 (i386, x86_64)
Comment 19 Swamp Workflow Management 2014-04-29 21:04:22 UTC
SUSE-SU-2014:0581-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 871097
CVE References: CVE-2014-0466
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    a2ps-4.13-1326.37.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    a2ps-4.13-1326.37.1
SUSE Linux Enterprise Server 11 SP3 (src):    a2ps-4.13-1326.37.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    a2ps-4.13-1326.37.1
Comment 20 Alexander Bergmann 2014-05-02 15:56:42 UTC
Fixed and released. Closing bug.