|
|
|
![]() |
Vulnerability Note VU#399883Linux groff utility pic contains format string vulnerabilityOverviewThe pic component of the image processing package groff contains a format string vulnerability that could allow a remote attacker to execute arbitrary code.I. Descriptiongroff is an image processing package on Linux systems. A component of groff called pic contains a format-string vulnerability that can be exploited to execute arbitrary code. Since groff and pic are used by lpd to render documents for printing, an attacker can craft a printer spool file to execute arbitrary code on an lpd print server.II. ImpactRemote attackers can cause execution of arbitrary code.III. SolutionApply a patch or upgradeApply a patch or upgrade as appropriate. See the Systems Affected section for more details.
References
Thanks to zen-parse for reporting this vulnerability. This document was written by Shawn Van Ittersum and Art Manion.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||