Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200507-29
https://security.gentoo.org/
Severity: Normal
Title: pstotext: Remote execution of arbitrary code
Date: July 31, 2005
Bugs: #100245
ID: 200507-29
Synopsis
=======
pstotext contains a vulnerability which can potentially result in the
execution of arbitrary code.
Background
=========
pstotext is a program that works with GhostScript to extract plain text
from PostScript and PDF files.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 app-text/pstotext < 1.8g-r1 >= 1.8g-r1
==========
Max Vozeler reported that pstotext calls the GhostScript interpreter on
untrusted PostScript files without specifying the -dSAFER option.
...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.