Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
75 changes: 75 additions & 0 deletions advisories/BREW-a2ps-CVE-2001-1593.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,75 @@
{
"schema_version": "1.7.3",
"id": "BREW-a2ps-CVE-2001-1593",
"published": "2026-08-09T08:35:19Z",
"modified": "2026-08-09T08:35:19Z",
"upstream": [
"CVE-2001-1593"
],
"affected": [
{
"package": {
"ecosystem": "Homebrew",
"name": "a2ps",
"purl": "pkg:brew/a2ps"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"ecosystem_specific": {
"fix": null
}
}
],
"database_specific": {
"source": "matched",
"strategy": "distro",
"confidence": "low",
"upstream_evidence": [
{
"strategy": "distro",
"ecosystem": "Debian",
"name": "a2ps",
"key": "Debian/a2ps"
}
]
},
"details": "The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.",
"references": [
{
"type": "ADVISORY",
"url": "http://www.debian.org/security/2014/dsa-2892"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1060630"
},
{
"type": "WEB",
"url": "http://pkgs.fedoraproject.org/cgit/a2ps.git/plain/a2ps-4.13-security.patch"
},
{
"type": "WEB",
"url": "http://seclists.org/oss-sec/2014/q1/237"
},
{
"type": "WEB",
"url": "http://seclists.org/oss-sec/2014/q1/253"
},
{
"type": "WEB",
"url": "http://seclists.org/oss-sec/2014/q1/257"
},
{
"type": "WEB",
"url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737385"
}
]
}
107 changes: 107 additions & 0 deletions advisories/BREW-a2ps-CVE-2004-1170.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,107 @@
{
"schema_version": "1.7.3",
"id": "BREW-a2ps-CVE-2004-1170",
"published": "2026-08-09T08:35:19Z",
"modified": "2026-08-09T08:35:19Z",
"upstream": [
"CVE-2004-1170"
],
"affected": [
{
"package": {
"ecosystem": "Homebrew",
"name": "a2ps",
"purl": "pkg:brew/a2ps"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"ecosystem_specific": {
"fix": null
}
}
],
"database_specific": {
"source": "matched",
"strategy": "distro",
"confidence": "low",
"upstream_evidence": [
{
"strategy": "distro",
"ecosystem": "Debian",
"name": "a2ps",
"key": "Debian/a2ps"
}
]
},
"details": "a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.",
"references": [
{
"type": "ADVISORY",
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1026.html"
},
{
"type": "ADVISORY",
"url": "http://secunia.com/advisories/12375"
},
{
"type": "ADVISORY",
"url": "http://www.mandriva.com/security/advisories?name=MDKSA-2004:140"
},
{
"type": "ADVISORY",
"url": "http://www.novell.com/linux/security/advisories/2004_34_xfree86_libs_xshared.html"
},
{
"type": "ADVISORY",
"url": "http://www.securityfocus.com/bid/11025"
},
{
"type": "EVIDENCE",
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1026.html"
},
{
"type": "EVIDENCE",
"url": "http://www.securityfocus.com/bid/11025"
},
{
"type": "FIX",
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1026.html"
},
{
"type": "FIX",
"url": "http://www.securityfocus.com/bid/11025"
},
{
"type": "WEB",
"url": "http://bugs.debian.org/283134"
},
{
"type": "WEB",
"url": "http://marc.info/?l=bugtraq&m=110598355226660&w=2"
},
{
"type": "WEB",
"url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-57649-1&searchclause="
},
{
"type": "WEB",
"url": "http://www.securiteam.com/unixfocus/5MP0N2KDPA.html"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/archive/1/419765/100/0/threaded"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/17127"
}
]
}
75 changes: 75 additions & 0 deletions advisories/BREW-a2ps-CVE-2004-1377.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,75 @@
{
"schema_version": "1.7.3",
"id": "BREW-a2ps-CVE-2004-1377",
"published": "2026-08-09T08:35:19Z",
"modified": "2026-08-09T08:35:19Z",
"upstream": [
"CVE-2004-1377"
],
"affected": [
{
"package": {
"ecosystem": "Homebrew",
"name": "a2ps",
"purl": "pkg:brew/a2ps"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"ecosystem_specific": {
"fix": null
}
}
],
"database_specific": {
"source": "matched",
"strategy": "distro",
"confidence": "low",
"upstream_evidence": [
{
"strategy": "distro",
"ecosystem": "Debian",
"name": "a2ps",
"key": "Debian/a2ps"
}
]
},
"details": "The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.",
"references": [
{
"type": "ADVISORY",
"url": "http://secunia.com/advisories/13641"
},
{
"type": "FIX",
"url": "http://www.gentoo.org/security/en/glsa/glsa-200501-02.xml"
},
{
"type": "FIX",
"url": "http://www.securityfocus.com/bid/12108"
},
{
"type": "FIX",
"url": "http://www.securityfocus.com/bid/12109"
},
{
"type": "WEB",
"url": "http://www.vuxml.org/freebsd/9168253c-5a6d-11d9-a9e7-0001020eed82.html"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18671"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18672"
}
]
}
67 changes: 67 additions & 0 deletions advisories/BREW-a2ps-CVE-2014-0466.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
{
"schema_version": "1.7.3",
"id": "BREW-a2ps-CVE-2014-0466",
"published": "2026-08-09T08:35:19Z",
"modified": "2026-08-09T08:35:19Z",
"upstream": [
"CVE-2014-0466"
],
"affected": [
{
"package": {
"ecosystem": "Homebrew",
"name": "a2ps",
"purl": "pkg:brew/a2ps"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"ecosystem_specific": {
"fix": null
}
}
],
"database_specific": {
"source": "matched",
"strategy": "distro",
"confidence": "low",
"upstream_evidence": [
{
"strategy": "distro",
"ecosystem": "Debian",
"name": "a2ps",
"key": "Debian/a2ps"
}
]
},
"details": "The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.",
"references": [
{
"type": "ADVISORY",
"url": "http://www.debian.org/security/2014/dsa-2892"
},
{
"type": "ADVISORY",
"url": "https://security.gentoo.org/glsa/201701-67"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-updates/2014-04/msg00021.html"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/66660"
},
{
"type": "WEB",
"url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742902"
}
]
}
65 changes: 65 additions & 0 deletions advisories/BREW-a2ps-CVE-2015-8107.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
{
"schema_version": "1.7.3",
"id": "BREW-a2ps-CVE-2015-8107",
"published": "2026-08-09T08:35:19Z",
"modified": "2026-08-09T08:35:19Z",
"upstream": [
"CVE-2015-8107"
],
"affected": [
{
"package": {
"ecosystem": "Homebrew",
"name": "a2ps",
"purl": "pkg:brew/a2ps"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"ecosystem_specific": {
"fix": null
}
}
],
"database_specific": {
"source": "matched",
"strategy": "distro",
"confidence": "low",
"upstream_evidence": [
{
"strategy": "distro",
"ecosystem": "Debian",
"name": "a2ps",
"key": "Debian/a2ps"
}
]
},
"details": "Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"references": [
{
"type": "ADVISORY",
"url": "http://seclists.org/oss-sec/2015/q4/284"
},
{
"type": "ADVISORY",
"url": "http://www.securityfocus.com/bid/77595"
},
{
"type": "ARTICLE",
"url": "http://seclists.org/oss-sec/2015/q4/284"
}
]
}
Loading