Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Mageia 3 released
· Understanding Email Bounce Messages and more
· How to Prepare for Windows 8 Even Though Its Not Coming to Enterprises
· Microsoft Office Clone Updates Interface, Improves File Support
· Windows Firewall Control 4.0.0.0 released
· 10 amazing Linux desktop environments you've probably never seen
· Microsoft Office security flaw hits thousands in latest hacker attack
· Kubuntu 13.04 Raring Ringtail Review
· Windows Mobile 7 concept video shows why Microsoft dumped the platform
· Building a Thin Mini-ITX PC and more

Upcoming News
· PowerColor PCS+ HD7870 Gaming Video Card @ TechwareLabs
· Rosewill T600N Wireless Router Review @ ThinkComputers.org
· Google Play Music Review @ TechReviewSource.com
· Adata DashDrive Elite UE700 32GB Flash Drive Review @ Ninjalane
· News: HGST packs 1.5TB into 9.5-mm, three-platter Travelstar 5K1500 notebook drive
· Gigabyte GeForce GTX 650 Ti Boost OC WindForce 2X review
· Metro: Last Light Performance, Benchmarked
· Seidio Active Case Combo for HTC One Review @ TestFreaks
· Jawbone UP Wristband
· Seagate Desktop HDD.15 4TB Hard Drive Review @ Hardware Canucks

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6394 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 662 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4523 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 724 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1120 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » January 2005 » USN-68-1: enscript vulnerabilities

USN-68-1: enscript vulnerabilities

Posted by Philipp Esselbach on: 01/24/2005 09:44 AM [ Print | 0 comment(s) ]

An enscript security update has been released for Ubuntu Linux 4.10

===========================================================
Ubuntu Security Notice USN-68-1 January 24, 2005
enscript vulnerabilities
CAN-2004-1184 CAN-2004-1185 CAN-2004-1186
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)

The following packages are affected:

enscript

The problem can be corrected by upgrading the affected package to version 1.6.4-4ubuntu0.1. In general, a standard system upgrade is sufficient to effect the necessary changes.




Details follow:

Erik Sjlund discovered several vulnerabilities in enscript which could cause arbitrary code execution with the privileges of the user calling enscript.

Quotes and other shell escape characters in titles and file names were not handled in previous versions. (CAN-2004-1184)

Previous versions supported reading EPS data not only from a file, but also from an arbitrary command pipe. Since checking for unwanted side effects is infeasible, this feature has been disabled after consultation with the authors of enscript. (CAN-2004-1185)

Finally, this update fixes two buffer overflows which were triggered by certain input files. (CAN-2004-1186)

These issues can lead to privilege escalation if enscript is called automatically from web server applications like viewcvs.

Source archives:

http://security.ubuntu.com/ubuntu/pool/universe/e/enscript/enscript_1.6
.4-4ubuntu0.1.diff.gz
Size/MD5: 15036 d6c873e923c34c39cc144030efc83dd5
http://security.ubuntu.com/ubuntu/pool/universe/e/enscript/enscript_1.6
.4-4ubuntu0.1.dsc
Size/MD5: 628 711d7f5bbf6018fe56f386a37cfb93ed
http://security.ubuntu.com/ubuntu/pool/universe/e/enscript/enscript_1.6
.4.orig.tar.gz
Size/MD5: 1036734 b5174b59e4a050fb462af5dbf28ebba3

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/universe/e/enscript/enscript_1.6
.4-4ubuntu0.1_amd64.deb
Size/MD5: 482748 5115fde125c8b21aabb0e381ad3d82a8

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/universe/e/enscript/enscript_1.6
.4-4ubuntu0.1_i386.deb
Size/MD5: 468824 88d3ae70ced661d02fdbd93178ca4d35

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/universe/e/enscript/enscript_1.6
.4-4ubuntu0.1_powerpc.deb
Size/MD5: 481268 b55c45bcf7cf0a941fb2021a0f8073de


Bookmark and Share

« Scythe Silent Box 3.5" HDD Enclosure without FAN · GARNOME 2.9.4.1 »

Linux Compatible » News » January 2005 » USN-68-1: enscript vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition