LWN.net Logo

enscript: stack overflows

Package(s):enscript CVE #(s):CVE-2008-3863 CVE-2008-4306
Created:November 4, 2008 Updated:December 16, 2008
Description: From the Ubuntu alert:

Ulf Härnhammar discovered multiple stack overflows in enscript's handling of special escape arguments. If a user or automated system were tricked into processing a malicious file with the "-e" option enabled, a remote attacker could execute arbitrary code or cause enscript to crash, possibly leading to a denial of service.

Alerts:
Mandriva MDVSA-2008:243 2008-12-15
CentOS CESA-2008:1016 2008-12-16
CentOS CESA-2008:1021 2008-12-15
Red Hat RHSA-2008:1016-01 2008-12-15
Red Hat RHSA-2008:1021-02 2008-12-15
Gentoo 200812-02 2008-12-02
Debian DSA-1670-1 2008-11-24
rPath rPSA-2008-0321-1 2008-11-17
SuSE SUSE-SR:2008:024 2008-11-07
Fedora FEDORA-2008-9372 2008-11-06
Fedora FEDORA-2008-9351 2008-11-06
Ubuntu USN-660-1 2008-11-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds