[SECURITY] Fedora Core 2 Update: enscript-1.6.1-25.2

Tim Waugh twaugh at redhat.com
Wed Jan 26 11:37:12 UTC 2005


---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2005-015
2005-01-26
---------------------------------------------------------------------

Product     : Fedora Core 2
Name        : enscript
Version     : 1.6.1                      
Release     : 25.2                  
Summary     : A plain ASCII to PostScript converter.
Description :
GNU enscript is a free replacement for Adobe's Enscript
program. Enscript converts ASCII files to PostScript(TM) and spools
generated PostScript output to the specified printer or saves it to a
file. Enscript can be extended to handle different output media and
includes many options for customizing printouts.

---------------------------------------------------------------------
Update Information:

Erik Sjölund has discovered several security relevant problems in
enscript, a program to converts ASCII text to Postscript and other
formats.  The Common Vulnerabilities and Exposures project identifies
the following vulnerabilities:

CAN-2004-1184

    Unsanitised input can caues the execution of arbitrary commands
    via EPSF pipe support.  This has been disabled, also upstream.

CAN-2004-1185

    Due to missing sanitising of filenames it is possible that a
    specially crafted filename can cause arbitrary commands to be
    executed.

CAN-2004-1186

    Multiple buffer overflows can cause the program to crash.

---------------------------------------------------------------------
* Mon Jan 24 2005 Tim Waugh <twaugh at redhat.com> 1.6.1-25.2

- Fixed patch for CAN-2004-1186 (bug #114684).

* Tue Jan 11 2005 Tim Waugh <twaugh at redhat.com> 1.6.1-25.1

- Added patch to fix CAN-2004-1186 (bug #114684).
- Added patch to fix CAN-2004-1185 (bug #114684).
- Backported patch to fix CAN-2004-1184 (bug #114684).


---------------------------------------------------------------------
This update can be downloaded from:
  http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

aa8a46ea612edcccad9c3a90812e7b87  SRPMS/enscript-1.6.1-25.2.src.rpm
333674557f54bd9e05ad7b57e91ccd97  x86_64/enscript-1.6.1-25.2.x86_64.rpm
d1042af5d9397370d41170d06ce07d23  x86_64/debug/enscript-debuginfo-1.6.1-25.2.x86_64.rpm
d42a75862ed92f3a01840c42cc476a45  i386/enscript-1.6.1-25.2.i386.rpm
15dab7f96309408804dc89b233984dbe  i386/debug/enscript-debuginfo-1.6.1-25.2.i386.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.  
---------------------------------------------------------------------

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://lists.fedoraproject.org/pipermail/announce/attachments/20050126/129bf451/attachment.bin 


More information about the announce mailing list