Summary
The remote host is missing an update to html2ps
announced via advisory DSA 192-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20192-1
Insight
The SuSE Security Team found a vulnerability in html2ps, a HTML to PostScript converter, that opened files based on unsanitized input insecurely. This problem can be exploited when html2ps is installed as filter within lrpng and the attacker has previously gained access to the lp account.
These problems have been fixed in version 1.0b3-1.1 for the current stable distribution (woody), in version 1.0b1-8.1 for the old stable distribution (potato) and in version 1.0b3-2 for the unstable distribution (sid).
We recommend that you upgrade your html2ps package.
Severity
Classification
-
CVE CVE-2002-1275 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities