CVE-2008-4306
published 2008-11-04CVE-2008-4306: Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.
PriorityP334critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.44%
82.5th percentile
Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | enscript | < enscript 1.6.4-13 (bookworm) | enscript 1.6.4-13 (bookworm) |
| gnu | enscript | >= 0 < 1.6.4-13 | 1.6.4-13 |
| gnu | enscript | >= 0 < 1.6.4-13 | 1.6.4-13 |
| gnu | enscript | >= 0 < 1.6.4-13 | 1.6.4-13 |
| gnu | enscript | >= 0 < 1.6.4-13 | 1.6.4-13 |
| ubuntu | linux | — | — |
| ubuntu | linux | — | — |
| ubuntu | linux | — | — |
| ubuntu | linux | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7jw6-96x5-9376: Buffer overflow in enscript before 1
ghsa_unreviewed·2022-05-02
CVE-2008-4306 [HIGH] CWE-119 GHSA-7jw6-96x5-9376: Buffer overflow in enscript before 1
Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.
OSV
CVE-2008-4306: Buffer overflow in enscript before 1
osv·2008-11-04·CVSS 9.3
CVE-2008-4306 [CRITICAL] CVE-2008-4306: Buffer overflow in enscript before 1
Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.
Ubuntu
enscript vulnerability
vendor_ubuntu·2008-11-03
CVE-2008-3863 enscript vulnerability
Title: enscript vulnerability
Summary: enscript vulnerability
Ulf Härnhammar discovered multiple stack overflows in enscript's handling of
special escape arguments. If a user or automated system were tricked into
processing a malicious file with the "-e" option enabled, a remote attacker
could execute arbitrary code or cause enscript to crash, possibly leading
to a denial of service.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
enscript: "font" special escape buffer overflows
vendor_redhat·2008-10-29·CVSS 9.3
CVE-2008-4306 [CRITICAL] enscript: "font" special escape buffer overflows
enscript: "font" special escape buffer overflows
Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.
Debian
CVE-2008-4306: enscript - Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, ...
vendor_debian·2008·CVSS 9.3
CVE-2008-4306 [CRITICAL] CVE-2008-4306: enscript - Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, ...
Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.
Scope: local
bookworm: resolved (fixed in 1.6.4-13)
bullseye: resolved (fixed in 1.6.4-13)
forky: resolved (fixed in 1.6.4-13)
sid: resolved (fixed in 1.6.4-13)
trixie: resolved (fixed in 1.6.4-13)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-5078 enscript: "epsf" special escape buffer overflows
bugzilla·2008-12-01·CVSS 7.6
CVE-2008-5078 [HIGH] CVE-2008-5078 enscript: "epsf" special escape buffer overflows
CVE-2008-5078 enscript: "epsf" special escape buffer overflows
While preparing updates for CVE-2008-3863 and CVE-2008-4306, we have discovered that enscript 1.6.1 (and possibly earlier versions) is affected by similar flaws affecting handling of epsf special escape.
Long file name specified as an argument for epsf special escape can cause buffer overflow in recognize_eps_file() in src/psgen.c, or in tilde_subst() in src/util.c due to unsafe use of strcpy or sprintf.
Identified flaws do not affect enscript 1.6.4.
Discussion:
Created attachment 325251
Patch for enscript 1.6.1 for CVE-2008-3863, CVE-2008-4306 and CVE-2008-5078
It also prevents few command line arguments parsing overflow, but those are not security flaws (no trust boundary crossed).
---
Created attachment 325695
Improv
Bugzilla
CVE-2008-4306 enscript: "font" special escape buffer overflows
bugzilla·2008-10-31·CVSS 7.6
CVE-2008-4306 [HIGH] CVE-2008-4306 enscript: "font" special escape buffer overflows
CVE-2008-4306 enscript: "font" special escape buffer overflows
Kees Cook and Tomas Hoger discovered multiple buffer overflows in enscript related to handling of the font{} special escape caused by an unsafe use of strcpy(). This can be exploited to cause a stack-based buffer overflow by tricking the user into converting a malicious file, , but requires that special escapes processing is enabled with the "-e" option (not enabled by default).
Issue is similar to recently reported setfilename{} special escape handling buffer overflow known as CVE-2008-3863.
Discussion:
Created attachment 322030
Proposed patch from Kees Cook (Ubuntu)
---
Created attachment 322031
Escape array indexing typo
While testing this, another minor typo was discovered in the escapes array indexing in the error c
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.htmlhttp://osvdb.org/49569http://rhn.redhat.com/errata/RHSA-2008-1021.htmlhttp://secunia.com/advisories/32521http://secunia.com/advisories/32530http://secunia.com/advisories/32753http://secunia.com/advisories/32854http://secunia.com/advisories/32970http://secunia.com/advisories/33109http://security.gentoo.org/glsa/glsa-200812-02.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2008-504.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0321http://www.debian.org/security/2008/dsa-1670http://www.mandriva.com/security/advisories?name=MDVSA-2008:243http://www.redhat.com/support/errata/RHSA-2008-1016.htmlhttp://www.securityfocus.com/archive/1/498385/100/0/threadedhttp://www.ubuntu.com/usn/usn-660-1https://issues.rpath.com/browse/RPL-2887https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10718https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00014.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-November/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.htmlhttp://osvdb.org/49569http://rhn.redhat.com/errata/RHSA-2008-1021.htmlhttp://secunia.com/advisories/32521http://secunia.com/advisories/32530http://secunia.com/advisories/32753http://secunia.com/advisories/32854http://secunia.com/advisories/32970http://secunia.com/advisories/33109http://security.gentoo.org/glsa/glsa-200812-02.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2008-504.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0321http://www.debian.org/security/2008/dsa-1670http://www.mandriva.com/security/advisories?name=MDVSA-2008:243http://www.redhat.com/support/errata/RHSA-2008-1016.htmlhttp://www.securityfocus.com/archive/1/498385/100/0/threadedhttp://www.ubuntu.com/usn/usn-660-1https://issues.rpath.com/browse/RPL-2887https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10718https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00014.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-November/msg00040.html
2008-11-04
Published