Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://www.gentoo.org/security/en/glsa/glsa-200502-03.xml http://www.vuxml.org/freebsd/72da8af6-7c75-11d9-8cc5-000854d03344.html
Insight
The following packages are affected:
enscript-a4
enscript-letter
enscript-letterdj
CVE-2004-1184
The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
CVE-2004-1185
Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.
CVE-2004-1186
Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).
Severity
Classification
-
CVE CVE-2004-1184, CVE-2004-1185, CVE-2004-1186 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities