LWN.net Logo

pstotext: insecure file name quoting

Package(s):pstotext CVE #(s):CVE-2006-5869
Created:November 27, 2006 Updated:November 29, 2006
Description: Brian May discovered that pstotext, a utility to extract plain text from Postscript and PDF files, performs insufficient quoting of file names, which allows execution of arbitrary shell commands.
Alerts:
Debian DSA-1220-1 2006-11-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds