PT-2008-1045 · Gnu+1 · Enscript+1
Ulf Härnhammar
·
Published
2008-11-04
·
Updated
2018-10-11
·
CVE-2008-4306
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
enscript versions 1.6.1 through 1.6.4
Description
The issue concerns multiple vulnerabilities in the enscript package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A buffer overflow in enscript before version 1.6.4 has an unknown impact and attack vectors, possibly related to the font escape sequence.
Recommendations
For enscript version 1.6.1, update to a version later than 1.6.4 to resolve the issue.
For enscript version 1.6.4, update to a version later than 1.6.4 to resolve the issue.
As a temporary workaround, consider restricting access to the enscript package until a patch is available.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Enscript