CVE-2004-1185

8 documents8 sources
Severity
7.5HIGH
EPSS
7.4%
top 8.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 21
Latest updateApr 29

Description

Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Debianenscript< 1.6.4-6+3
NVDgnu/enscript7 versions+6

Patches

🔴Vulnerability Details

3
GHSA
GHSA-8xcw-4f7q-cw3g: Enscript 12022-04-29
CVEList
CVE-2004-1185: Enscript 12005-01-29
OSV
CVE-2004-1185: Enscript 12005-01-21

📋Vendor Advisories

3
Ubuntu
enscript vulnerabilities2005-01-24
Red Hat
security flaw2005-01-20
Debian
CVE-2004-1185: enscript - Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or loc...2004

💬Community

1
Bugzilla
CVE-2004-1185 security flaw2018-08-16
CVE-2004-1185 (HIGH CVSS 7.5) | Enscript 1.6.3 does not sanitize fi | cvebase.io