First published: Mon Dec 15 2008(Updated: )
GNU enscript converts ASCII files to PostScript(R) language files and<br>spools the generated output to a specified printer or saves it to a file.<br>Enscript can be extended to handle different output media and includes<br>options for customizing printouts.<br>Two buffer overflow flaws were found in GNU enscript. An attacker could<br>craft an ASCII file in such a way that it could execute arbitrary commands<br>if the file was opened with enscript with the "special escapes" option (-e<br>or --escapes) enabled. (CVE-2008-3863, CVE-2008-4306)<br>All users of enscript should upgrade to these updated packages, which<br>contain backported patches to correct these issues.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/enscript | <1.6.4-4.1.1.el5_2 | 1.6.4-4.1.1.el5_2 |
redhat/enscript | <1.6.4-4.1.1.el5_2 | 1.6.4-4.1.1.el5_2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.