enscript: ASCII to PostScript(tm) converter ---------------------------------------------------------------------- File: enscript-1.6.2-822.i586.rpm Patchrpm: enscript-1.6.2-822.i586.patch.rpm Version: 1.6.2-822 Size: 286 kB Patchsize: 73 kB Date: Thu 10 Feb 2005 12:27:24 CET Source: enscript-1.6.2-822.src.rpm Security: Yes ---------------------------------------------------------------------- Description: Unsanitised input can caues the execution of arbitrary commands via EPSF pipe support. This has been disabled, also upstream (CAN-2004-1184). Due to missing sanitising of filenames it is possible that a specially crafted filename can cause arbitrary commands to be executed (CAN-2004-1185). Multiple buffer overflows can cause the program to crash (CAN-2004-1186).