Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2002-0836
Description:dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.
Test IDs: 1.3.6.1.4.1.25623.1.0.53450   1.3.6.1.4.1.25623.1.0.51546   1.3.6.1.4.1.25623.1.0.50951   1.3.6.1.4.1.25623.1.0.50843   1.3.6.1.4.1.25623.1.0.50842  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2002-0836
BugTraq ID: 5978
http://www.securityfocus.com/bid/5978
Bugtraq: 20021018 GLSA: tetex (Google Search)
http://marc.info/?l=bugtraq&m=103497852330838&w=2
Bugtraq: 20021216 [OpenPKG-SA-2002.015] OpenPKG Security Advisory (tetex) (Google Search)
http://marc.info/?l=bugtraq&m=104005975415582&w=2
CERT/CC vulnerability note: VU#169841
http://www.kb.cert.org/vuls/id/169841
Conectiva Linux advisory: CLA-2002:537
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000537
Debian Security Information: DSA-207 (Google Search)
http://www.debian.org/security/2002/dsa-207
HPdes Security Advisory: HPSBTL0210-073
http://www.securityfocus.com/advisories/4567
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-070.php
RedHat Security Advisories: RHSA-2002:194
http://www.redhat.com/support/errata/RHSA-2002-194.html
RedHat Security Advisories: RHSA-2002:195
http://www.redhat.com/support/errata/RHSA-2002-195.html
XForce ISS Database: dvips-system-execute-commands(10365)
http://www.iss.net/security_center/static/10365.php




© 1998-2025 E-Soft Inc. All rights reserved.