Advisories Blog | G5 Cyber Security

secunia-enscript.txt

Secunia Research has discovered a vulnerability in GNU Enscript, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to a boundary error within the “read_special_escape()” function in src/psgen.c. This can be exploited to cause a stack-based buffer overflow by tricking the user into converting a malicious file. Successful exploitation allows execution of arbitrary code, but requires that special escapes processing is enabled with the “-e” option. GNU Enscript versions 1.6.1 and 1.6.4 beta are vulnerable.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/71132/secunia-enscript.txt

Source: https://packetstormsecurity.com/files/71132/secunia-enscript.txt.html

Exit mobile version