CVE-2004-1170 describes a critical command injection vulnerability in a2ps version 4.13, impacting various GNU, Sun, and SUSE Linux distributions. This flaw allows unauthenticated remote attackers to execute arbitrary commands by embedding shell metacharacters within filenames. With a CVSS score of 10.0, this vulnerability presents a severe risk due to its low attack complexity and complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, exploit code is publicly available via ExploitDB, and the vulnerability has garnered significant community discussion, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.13CPE matchmatch criteria | cpe:2.3:a:gnu:a2ps:4.13:*:*:*:*:*:*:* | ||
4.13bCPE matchmatch criteria | cpe:2.3:a:gnu:a2ps:4.13b:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:sun:java_desktop_system:2.0:*:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:sun:java_desktop_system:2003:*:*:*:*:*:*:* | ||
8CPE matchmatch criteria | cpe:2.3:o:suse:suse_linux:8:*:enterprise_server:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.