CVE-2002-0836
UnknownEPSS 7.95%
Last modified
CVE-2002-0836 is a vulnerability of currently unknown severity. dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.. EPSS estimates a 7.95% chance of exploitation in the next 30 days.
Description
dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Secure Os | 1.0 |
| Mandrakesoft | Mandrake Linux | 7.2 |
| Mandrakesoft | Mandrake Linux | 8.0 |
| Mandrakesoft | Mandrake Linux | 8.1 |
| Mandrakesoft | Mandrake Linux | 8.2 |
| Mandrakesoft | Mandrake Linux | 9.0 |
| Redhat | Linux | 6.2 |
| Redhat | Linux | 7.0 |
| Redhat | Linux | 7.1 |
| Redhat | Linux | 7.2 |
| Redhat | Linux | 7.3 |
| Redhat | Linux | 8.0 |
References
- http://www.debian.org/security/2002/dsa-207Patch, Vendor Advisory
- http://www.iss.net/security_center/static/10365.phpVendor Advisory
- http://www.kb.cert.org/vuls/id/169841US Government Resource
- http://www.redhat.com/support/errata/RHSA-2002-194.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/5978Patch, Vendor Advisory
- http://www.debian.org/security/2002/dsa-207Patch, Vendor Advisory
- http://www.iss.net/security_center/static/10365.phpVendor Advisory
- http://www.kb.cert.org/vuls/id/169841US Government Resource
- http://www.redhat.com/support/errata/RHSA-2002-194.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/5978Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0836?
dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.
How severe is CVE-2002-0836?
Severity scoring for CVE-2002-0836 is pending analysis. The EPSS model estimates a 7.95% probability of exploitation in the next 30 days.
How do I fix CVE-2002-0836?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-0830Network File System (NFS) in FreeBSD 4.6.1 RELEASE-p7 and ea…
- CVE-2002-0831The kqueue mechanism in FreeBSD 4.3 through 4.6 STABLE allow…
- CVE-2002-0832Internet Explorer 5, 5.6, and 6 allows remote attackers to b…
- CVE-2002-0833Buffer overflow in Eudora 5.1.1 and 5.0-J for Windows, and p…
- CVE-2002-0834Buffer overflow in the ISIS dissector for Ethereal 0.9.5 and…
- CVE-2002-0835Preboot eXecution Environment (PXE) server allows remote att…
- CVE-2002-0837wordtrans 1.1pre8 and earlier in the wordtrans-web package a…
- CVE-2002-0838Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 a…
- CVE-2002-0839The shared memory scoreboard in the HTTP daemon for Apache 1…
- CVE-2002-0840Cross-site scripting (XSS) vulnerability in the default erro…
- CVE-2002-0841Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2002-0842Format string vulnerability in certain third party modificat…
Are you affected by CVE-2002-0836?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
