CVE-2008-5078

Publication date 19 December 2008

Last updated 24 July 2024


Ubuntu priority

Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen.c) and (2) tilde_subst function (src/util.c) in GNU enscript 1.6.1, and possibly earlier, might allow remote attackers to execute arbitrary code via an epsf escape sequence with a long filename.

Read the notes from the security team

Status

Package Ubuntu Release Status
enscript 8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
6.06 LTS dapper
Not affected

Notes


mdeslaur

flaws do not affect enscript 1.6.4 as per redhat bug