CVE-2008-4306

Severity
9.3CRITICAL
EPSS
4.7%
top 10.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 4
Latest updateMay 2

Description

Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

â–¶Debianenscript< 1.6.4-13+3
â–¶NVDubuntu/linux4 versions+3

🔴Vulnerability Details

3
GHSA
GHSA-7jw6-96x5-9376: Buffer overflow in enscript before 1↗2022-05-02
â–¶
OSV
CVE-2008-4306: Buffer overflow in enscript before 1↗2008-11-04
â–¶
CVEList
CVE-2008-4306: Buffer overflow in enscript before 1↗2008-11-04
â–¶

📋Vendor Advisories

3
Ubuntu
enscript vulnerability↗2008-11-03
â–¶
Red Hat
enscript: "font" special escape buffer overflows↗2008-10-29
â–¶
Debian
CVE-2008-4306: enscript - Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, ...↗2008
â–¶

💬Community

2
Bugzilla
CVE-2008-5078 enscript: "epsf" special escape buffer overflows↗2008-12-01
â–¶
Bugzilla
CVE-2008-4306 enscript: "font" special escape buffer overflows↗2008-10-31
â–¶
CVE-2008-4306 (CRITICAL CVSS 9.3) | Buffer overflow in enscript before | cvebase.io