The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains malicious commands.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=99892644616749&w=2 | |
http://www.redhat.com/support/errata/RHSA-2001-102.html | Patch Vendor Advisory |
http://www.securityfocus.com/bid/3241 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16509 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2002-06-25T04:00:00
Updated: 2002-06-16T00:00:00
Reserved: 2002-01-31T00:00:00
Link: CVE-2001-1002
JSON object: View
NVD Information
Status : Modified
Published: 2001-08-31T04:00:00.000
Modified: 2017-10-10T01:29:57.890
Link: CVE-2001-1002
JSON object: View
Redhat Information
No data.
CWE