Date: Tue, 16 Dec 2008 13:36:23 -0600 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for enscript on SL3.x, SL4.x, SL5.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Moderate: enscript security update Issue date: 2008-12-15 CVE Names: CVE-2008-3863 CVE-2008-4306 CVE-2008-5078 Several buffer overflow flaws were found in GNU enscript. An attacker could craft an ASCII file in such a way that it could execute arbitrary commands if the file was opened with enscript with the "special escapes" option (-e or --escapes) enabled. (CVE-2008-3863, CVE-2008-4306, CVE-2008-5078) SL 3.0.x SRPMS: enscript-1.6.1-24.7.src.rpm i386: enscript-1.6.1-24.7.i386.rpm x86_64: enscript-1.6.1-24.7.x86_64.rpm SL 4.x SRPMS: enscript-1.6.1-33.el4_7.1.src.rpm i386: enscript-1.6.1-33.el4_7.1.i386.rpm x86_64: enscript-1.6.1-33.el4_7.1.x86_64.rpm SL 5.x SRPMS: enscript-1.6.4-4.1.1.el5_2.src.rpm i386: enscript-1.6.4-4.1.1.el5_2.i386.rpm x86_64: enscript-1.6.4-4.1.1.el5_2.x86_64.rpm -Connie Sieh -Troy Dawson