The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade a2ps | Jul 30, 2024 | Dec 27, 2004 |
| Freebsd | — | Upgrade a2ps-letterdjUpgrade a2ps-a4Upgrade a2ps-letter | Dec 10, 2025 | Dec 30, 2004 |
| Gentoo Linux | — | Upgrade app-text/a2ps. | Oct 30, 2017 | Dec 27, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub