CVE-2004-1185
published 2005-01-21CVE-2004-1185: Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.
PriorityP337high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.48%
90.4th percentile
Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | enscript | < enscript 1.6.4-6 (bookworm) | enscript 1.6.4-6 (bookworm) |
| gnu | enscript | — | — |
| gnu | enscript | — | — |
| gnu | enscript | — | — |
| gnu | enscript | — | — |
| gnu | enscript | — | — |
| gnu | enscript | — | — |
| gnu | enscript | — | — |
| gnu | enscript | >= 0 < 1.6.4-6 | 1.6.4-6 |
| gnu | enscript | >= 0 < 1.6.4-6 | 1.6.4-6 |
| gnu | enscript | >= 0 < 1.6.4-6 | 1.6.4-6 |
| gnu | enscript | >= 0 < 1.6.4-6 | 1.6.4-6 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
enscript vulnerabilities
vendor_ubuntu·2005-01-24
CVE-2004-1184 enscript vulnerabilities
Title: enscript vulnerabilities
Summary: enscript vulnerabilities
Erik Sjölund discovered several vulnerabilities in enscript which
could cause arbitrary code execution with the privileges of the user
calling enscript.
Quotes and other shell escape characters in titles and file names were
not handled in previous versions. (CAN-2004-1184)
Previous versions supported reading EPS data not only from a file, but
also from an arbitrary command pipe. Since checking for unwanted side
effects is infeasible, this feature has been disabled after
consultation with the authors of enscript. (CAN-2004-1185)
Finally, this update fixes two buffer overflows which were triggered by
certain input files. (CAN-2004-1186)
These issues can lead to privilege escalation if enscript is called
automatically fro
Red Hat
security flaw
vendor_redhat·2005-01-20·CVSS 7.5
CVE-2004-1185 [HIGH] security flaw
security flaw
Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2004-1185: enscript - Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or loc...
vendor_debian·2004·CVSS 7.5
CVE-2004-1185 [HIGH] CVE-2004-1185: enscript - Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or loc...
Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.
Scope: local
bookworm: resolved (fixed in 1.6.4-6)
bullseye: resolved (fixed in 1.6.4-6)
forky: resolved (fixed in 1.6.4-6)
sid: resolved (fixed in 1.6.4-6)
trixie: resolved (fixed in 1.6.4-6)
GHSA
GHSA-8xcw-4f7q-cw3g: Enscript 1
ghsa_unreviewed·2022-04-29
CVE-2004-1185 [HIGH] GHSA-8xcw-4f7q-cw3g: Enscript 1
Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.
OSV
CVE-2004-1185: Enscript 1
osv·2005-01-21·CVSS 7.5
CVE-2004-1185 [HIGH] CVE-2004-1185: Enscript 1
Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://secunia.com/advisories/35074http://securitytracker.com/id?1012965http://support.apple.com/kb/HT3549http://www.debian.org/security/2005/dsa-654http://www.gentoo.org/security/en/glsa/glsa-200502-03.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:033http://www.redhat.com/support/errata/RHSA-2005-040.htmlhttp://www.securityfocus.com/archive/1/419768/100/0/threadedhttp://www.securityfocus.com/archive/1/435199/100/0/threadedhttp://www.securityfocus.com/bid/12329http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297https://exchange.xforce.ibmcloud.com/vulnerabilities/19029https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10808https://usn.ubuntu.com/68-1/http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://secunia.com/advisories/35074http://securitytracker.com/id?1012965http://support.apple.com/kb/HT3549http://www.debian.org/security/2005/dsa-654http://www.gentoo.org/security/en/glsa/glsa-200502-03.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:033http://www.redhat.com/support/errata/RHSA-2005-040.htmlhttp://www.securityfocus.com/archive/1/419768/100/0/threadedhttp://www.securityfocus.com/archive/1/435199/100/0/threadedhttp://www.securityfocus.com/bid/12329http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297https://exchange.xforce.ibmcloud.com/vulnerabilities/19029https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10808https://usn.ubuntu.com/68-1/
2005-01-21
Published