CVE-2008-4306: Buffer Overflow
Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.
Other sources
Kees Cook and Tomas Hoger discovered multiple buffer overflows in enscript related to handling of the font{} special escape caused by an unsafe use of strcpy(). This can be exploited to cause a stack-based buffer overflow by tricking the user into converting a malicious file, , but requires that special escapes processing is enabled with the "-e" option (not enabled by default).
Issue is similar to recently reported setfilename{} special escape handling buffer overflow known as CVE-2008-3863.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2008-4306?
CVE-2008-4306 has an unknown severity due to the lack of detailed information regarding its impact and attack vectors.
How do I fix CVE-2008-4306?
To fix CVE-2008-4306, upgrade to enscript version 1.6.4 or later.
Which versions of enscript are affected by CVE-2008-4306?
CVE-2008-4306 affects enscript versions prior to 1.6.4, including 1.6.1-33.el4_7.1 and earlier.
What is the primary vulnerability type of CVE-2008-4306?
CVE-2008-4306 is primarily a buffer overflow vulnerability.
Are there any known exploits for CVE-2008-4306?
There are currently no specific known exploits for CVE-2008-4306 due to its unspecified impact and attack vectors.