Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora: 2023-4601 Urgent: Fix For Enscrip Buffer Overflow

fedora
Calendar Grey November 5, 2008
Dist Fedora Esm H88
Important patch released for Fedora addressing vulnerabilities in enscript related to buffer overflows. Make sure to update to protect your system.
There were found various buffer overflows in enscript

Summary

GNU enscript is a free replacement for Adobe's Enscript

program. Enscript converts ASCII files to PostScript(TM) and spools

generated PostScript output to the specified printer or saves it to a

file. Enscript can be extended to handle different output media and

includes many options for customizing printouts.

There were found various buffer overflows in enscript. This update fixes

CVE-2008-3863 and CVE-2008-4306

* Mon Nov 3 2008 Adam Tkac 1.6.4-9

- fixed various buffer overflows (CVE-2008-3863, CVE-2008-4306)

[ 1 ] Bug #466771 - CVE-2008-3863 enscript: "setfilename" special escape buffer overflow

https://bugzilla.redhat.com/show_bug.cgi?id=466771

[ 2 ] Bug #469311 - CVE-2008-4306 enscript: "font" special escape buffer overflows

https://bugzilla.redhat.com/show_bug.cgi?id=469311

su -c 'yum update enscript' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 8
Version: 1.6.4
Release: 9.fc8
URL: Summary : A plain ASCII to PostScript converter.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here