CVE-2004-1186
published 2004-12-31CVE-2004-1186: Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).
PriorityP415medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.98%
89.4th percentile
Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | enscript | < enscript 1.6.4-6 (bookworm) | enscript 1.6.4-6 (bookworm) |
| gnu | enscript | — | — |
| gnu | enscript | >= 0 < 1.6.4-6 | 1.6.4-6 |
| gnu | enscript | >= 0 < 1.6.4-6 | 1.6.4-6 |
| gnu | enscript | >= 0 < 1.6.4-6 | 1.6.4-6 |
| gnu | enscript | >= 0 < 1.6.4-6 | 1.6.4-6 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
enscript vulnerabilities
vendor_ubuntu·2005-01-24
CVE-2004-1184 enscript vulnerabilities
Title: enscript vulnerabilities
Summary: enscript vulnerabilities
Erik Sjölund discovered several vulnerabilities in enscript which
could cause arbitrary code execution with the privileges of the user
calling enscript.
Quotes and other shell escape characters in titles and file names were
not handled in previous versions. (CAN-2004-1184)
Previous versions supported reading EPS data not only from a file, but
also from an arbitrary command pipe. Since checking for unwanted side
effects is infeasible, this feature has been disabled after
consultation with the authors of enscript. (CAN-2004-1185)
Finally, this update fixes two buffer overflows which were triggered by
certain input files. (CAN-2004-1186)
These issues can lead to privilege escalation if enscript is called
automatically fro
Red Hat
security flaw
vendor_redhat·2005-01-20·CVSS 5.0
CVE-2004-1186 [MEDIUM] security flaw
security flaw
Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2004-1186: enscript - Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local user...
vendor_debian·2004·CVSS 5.0
CVE-2004-1186 [MEDIUM] CVE-2004-1186: enscript - Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local user...
Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).
Scope: local
bookworm: resolved (fixed in 1.6.4-6)
bullseye: resolved (fixed in 1.6.4-6)
forky: resolved (fixed in 1.6.4-6)
sid: resolved (fixed in 1.6.4-6)
trixie: resolved (fixed in 1.6.4-6)
GHSA
GHSA-wwp7-qc43-6cph: Multiple buffer overflows in enscript 1
ghsa_unreviewed·2022-04-29
CVE-2004-1186 [MEDIUM] GHSA-wwp7-qc43-6cph: Multiple buffer overflows in enscript 1
Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).
OSV
CVE-2004-1186: Multiple buffer overflows in enscript 1
osv·2004-12-31·CVSS 5.0
CVE-2004-1186 [MEDIUM] CVE-2004-1186: Multiple buffer overflows in enscript 1
Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://secunia.com/advisories/35074http://securitytracker.com/id?1012965http://support.apple.com/kb/HT3549http://www.debian.org/security/2005/dsa-654http://www.gentoo.org/security/en/glsa/glsa-200502-03.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:033http://www.redhat.com/support/errata/RHSA-2005-040.htmlhttp://www.securityfocus.com/archive/1/419768/100/0/threadedhttp://www.securityfocus.com/archive/1/435199/100/0/threadedhttp://www.securityfocus.com/bid/12329http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297https://exchange.xforce.ibmcloud.com/vulnerabilities/19033https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11134https://usn.ubuntu.com/68-1/http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://secunia.com/advisories/35074http://securitytracker.com/id?1012965http://support.apple.com/kb/HT3549http://www.debian.org/security/2005/dsa-654http://www.gentoo.org/security/en/glsa/glsa-200502-03.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:033http://www.redhat.com/support/errata/RHSA-2005-040.htmlhttp://www.securityfocus.com/archive/1/419768/100/0/threadedhttp://www.securityfocus.com/archive/1/435199/100/0/threadedhttp://www.securityfocus.com/bid/12329http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297https://exchange.xforce.ibmcloud.com/vulnerabilities/19033https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11134https://usn.ubuntu.com/68-1/
2004-12-31
Published