OpenBSD VuXML: Documenting security issues in the OpenBSD Ports & Packages Collection

enscript -- multiple vulnerabilities

Affected packages
enscript < 1.6.3p0

Details

VuXML ID 739b674e-7c75-11d9-8f68-080020fe8945
Discovery 2005-02-02
Entry 2005-02-11

Erik Sjolund discovered several issues in enscript. It suffers from several buffer overflows, quotes and shell escape characters are insufficiently sanitized in filenames, and it supported taking input from an arbitrary command pipe, with unwanted side effects.

References

CVE Name CAN-2004-1184
CVE Name CAN-2004-1185
CVE Name CAN-2004-1186