Bugzilla – Bug 33807
VUL-0: CVE-2002-0836: Security issues in dvips/xdvi
Last modified: 2021-09-28 07:54:56 UTC
dvips and xdvi do not properly check for funny font names in dvi files. This can be exploited by putting font names including ";/bin/rm -rf ~" etcinto the DVI file. In particular, this bug can probably be exploited to gain privileges of uid "lp" by submitting a DVI file to the print system and have it auto-converted to PostScript. patch attached; will test it
Created attachment 10340 [details] proposed patch
Submitted fixed package
CVE-2002-0836
CVE-2002-0836: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)