CVE-2005-2471

Publication date 5 August 2005

Last updated 24 July 2024


Ubuntu priority

pstopnm in netpbm does not properly use the "-dSAFER" option when calling Ghostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3) PNM file, which allows external user-assisted attackers to execute arbitrary commands.

Status

Package Ubuntu Release Status
netpbm-free 7.04 feisty
Fixed 10.0-10ubuntu1
6.10 edgy
Fixed 10.0-10ubuntu1
6.06 LTS dapper
Fixed 10.0-10ubuntu1

References

Related Ubuntu Security Notices (USN)

    • USN-164-1
    • netpbm vulnerability
    • 11 August 2005

Other references