Vulnerabilities > CVE-2005-2536 - Unspecified vulnerability in Pstotext

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
pstotext
nessus

Summary

pstotext before 1.8g does not properly use the "-dSAFER" option when calling Ghostscript to extract plain text from PostScript and PDF files, which allows remote attackers to execute arbitrary commands via a malicious PostScript file.

Vulnerable Configurations

Part Description Count
Application
Pstotext
1

Nessus

  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200507-29.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200507-29 (pstotext: Remote execution of arbitrary code) Max Vozeler reported that pstotext calls the GhostScript interpreter on untrusted PostScript files without specifying the -dSAFER option. Impact : An attacker could craft a malicious PostScript file and entice a user to run pstotext on it, resulting in the execution of arbitrary commands with the permissions of the user running pstotext. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id19360
    published2005-08-01
    reporterThis script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/19360
    titleGLSA-200507-29 : pstotext: Remote execution of arbitrary code
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-792.NASL
    descriptionMax Vozeler discovered that pstotext, a utility to extract text from PostScript and PDF files, did not execute ghostscript with the -dSAFER argument, which prevents potential malicious operations to happen.
    last seen2020-06-01
    modified2020-06-02
    plugin id19562
    published2005-09-06
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/19562
    titleDebian DSA-792-1 : pstotext - missing input sanitising