CVE-2004-1184
published 2005-01-21CVE-2004-1184: The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
PriorityP425medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
1.18%
64.2th percentile
The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | enscript | < enscript 1.6.4-6 (bookworm) | enscript 1.6.4-6 (bookworm) |
| gnu | enscript | — | — |
| gnu | enscript | — | — |
| gnu | enscript | — | — |
| gnu | enscript | — | — |
| gnu | enscript | — | — |
| gnu | enscript | — | — |
| gnu | enscript | — | — |
| gnu | enscript | >= 0 < 1.6.4-6 | 1.6.4-6 |
| gnu | enscript | >= 0 < 1.6.4-6 | 1.6.4-6 |
| gnu | enscript | >= 0 < 1.6.4-6 | 1.6.4-6 |
| gnu | enscript | >= 0 < 1.6.4-6 | 1.6.4-6 |
| redhat | fedora_core | — | — |
| redhat | fedora_core | — | — |
| sgi | propack | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
enscript vulnerabilities
vendor_ubuntu·2005-01-24
CVE-2004-1184 enscript vulnerabilities
Title: enscript vulnerabilities
Summary: enscript vulnerabilities
Erik Sjölund discovered several vulnerabilities in enscript which
could cause arbitrary code execution with the privileges of the user
calling enscript.
Quotes and other shell escape characters in titles and file names were
not handled in previous versions. (CAN-2004-1184)
Previous versions supported reading EPS data not only from a file, but
also from an arbitrary command pipe. Since checking for unwanted side
effects is infeasible, this feature has been disabled after
consultation with the authors of enscript. (CAN-2004-1185)
Finally, this update fixes two buffer overflows which were triggered by
certain input files. (CAN-2004-1186)
These issues can lead to privilege escalation if enscript is called
automatically fro
Red Hat
security flaw
vendor_redhat·2005-01-20·CVSS 4.6
CVE-2004-1184 [MEDIUM] security flaw
security flaw
The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
Debian
CVE-2004-1184: enscript - The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users t...
vendor_debian·2004·CVSS 4.6
CVE-2004-1184 [MEDIUM] CVE-2004-1184: enscript - The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users t...
The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
Scope: local
bookworm: resolved (fixed in 1.6.4-6)
bullseye: resolved (fixed in 1.6.4-6)
forky: resolved (fixed in 1.6.4-6)
sid: resolved (fixed in 1.6.4-6)
trixie: resolved (fixed in 1.6.4-6)
GHSA
GHSA-m3q3-jjv2-53w5: The EPSF pipe support in enscript 1
ghsa_unreviewed·2022-04-29
CVE-2004-1184 [MEDIUM] GHSA-m3q3-jjv2-53w5: The EPSF pipe support in enscript 1
The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
OSV
CVE-2004-1184: The EPSF pipe support in enscript 1
osv·2005-01-21·CVSS 4.6
CVE-2004-1184 [MEDIUM] CVE-2004-1184: The EPSF pipe support in enscript 1
The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
No detection rules found.
http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://secunia.com/advisories/35074http://securitytracker.com/id?1012965http://support.apple.com/kb/HT3549http://www.debian.org/security/2005/dsa-654http://www.gentoo.org/security/en/glsa/glsa-200502-03.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:033http://www.redhat.com/support/errata/RHSA-2005-040.htmlhttp://www.securityfocus.com/archive/1/419768/100/0/threadedhttp://www.securityfocus.com/archive/1/435199/100/0/threadedhttp://www.securityfocus.com/bid/12329http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297https://exchange.xforce.ibmcloud.com/vulnerabilities/19012https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9658https://usn.ubuntu.com/68-1/http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://secunia.com/advisories/35074http://securitytracker.com/id?1012965http://support.apple.com/kb/HT3549http://www.debian.org/security/2005/dsa-654http://www.gentoo.org/security/en/glsa/glsa-200502-03.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:033http://www.redhat.com/support/errata/RHSA-2005-040.htmlhttp://www.securityfocus.com/archive/1/419768/100/0/threadedhttp://www.securityfocus.com/archive/1/435199/100/0/threadedhttp://www.securityfocus.com/bid/12329http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297https://exchange.xforce.ibmcloud.com/vulnerabilities/19012https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9658https://usn.ubuntu.com/68-1/
2005-01-21
Published