CVE-2001-1002
The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains malicious commands.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 9.32% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- redhat/linux
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=99892644616749&w=2
- http://www.redhat.com/support/errata/RHSA-2001-102.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/3241Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16509
- http://marc.info/?l=bugtraq&m=99892644616749&w=2
- http://www.redhat.com/support/errata/RHSA-2001-102.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/3241Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16509
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.