Vulnerabilities > CVE-2005-2536 - Unspecified vulnerability in Pstotext

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
pstotext
nessus

Summary

pstotext before 1.8g does not properly use the "-dSAFER" option when calling Ghostscript to extract plain text from PostScript and PDF files, which allows remote attackers to execute arbitrary commands via a malicious PostScript file.

Vulnerable Configurations

Part Description Count
Application
Pstotext
1

Nessus

  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200507-29.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200507-29 (pstotext: Remote execution of arbitrary code) Max Vozeler reported that pstotext calls the GhostScript interpreter on untrusted PostScript files without specifying the -dSAFER option. Impact : An attacker could craft a malicious PostScript file and entice a user to run pstotext on it, resulting in the execution of arbitrary commands with the permissions of the user running pstotext. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id19360
    published2005-08-01
    reporterThis script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/19360
    titleGLSA-200507-29 : pstotext: Remote execution of arbitrary code
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-792.NASL
    descriptionMax Vozeler discovered that pstotext, a utility to extract text from PostScript and PDF files, did not execute ghostscript with the -dSAFER argument, which prevents potential malicious operations to happen.
    last seen2020-06-01
    modified2020-06-02
    plugin id19562
    published2005-09-06
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/19562
    titleDebian DSA-792-1 : pstotext - missing input sanitising