gv 3.5.8, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the filename for (1) a PDF file or (2) a gzip file.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/5840 | vdb entry patch vendor advisory |
http://www.epita.fr/~bevand_m/asa/asa-0000 | exploit patch vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2002-10/0033.html | mailing list |
http://marc.info/?l=bugtraq&m=103348446009076&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/10231 | vdb entry |