FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

enscript -- multiple vulnerabilities

Affected packages
enscript-a4 < 1.6.4_1
enscript-letter < 1.6.4_1
enscript-letterdj < 1.6.4_1

Details

VuXML ID 72da8af6-7c75-11d9-8cc5-000854d03344
Discovery 2005-02-02
Entry 2005-02-11

Erik Sjölund discovered several issues in enscript: it suffers from several buffer overflows, quotes and shell escape characters are insufficiently sanitized in filenames, and it supported taking input from an arbitrary command pipe, with unwanted side effects.

References

CVE Name CVE-2004-1184
CVE Name CVE-2004-1185
CVE Name CVE-2004-1186
URL http://www.gentoo.org/security/en/glsa/glsa-200502-03.xml