CVE-2001-1593
a2ps - security update
EPSS 0.40%
描述
The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.
如何修補 CVE-2001-1593
要修補 CVE-2001-1593,請將受影響套件升級到下列已修補版本。
- Debian/a2ps—升級至 1:4.14-1.2 或更新版本
- Debian/a2ps—升級至 1:4.14-1.1+deb6u1 或更新版本
CVE-2001-1593 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 1:4.14-1.2
- from 0, < 1:4.14-1.1+deb6u1