CVE Vulnerabilities

CVE-2004-1185

Published: Jan 21, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.

Affected Software

NameVendorStart VersionEnd Version
EnscriptGnu1.3.0 (including)1.3.0 (including)
EnscriptGnu1.4.0 (including)1.4.0 (including)
EnscriptGnu1.5.0 (including)1.5.0 (including)
EnscriptGnu1.6.0 (including)1.6.0 (including)
EnscriptGnu1.6.1 (including)1.6.1 (including)
EnscriptGnu1.6.2 (including)1.6.2 (including)
EnscriptGnu1.6.3 (including)1.6.3 (including)
Red Hat Enterprise Linux 3RedHatenscript-0:1.6.1-24.4*
Red Hat Enterprise Linux 4RedHatenscript-0:1.6.1-28.3*
EnscriptUbuntudapper*
EnscriptUbuntudevel*
EnscriptUbuntuedgy*
EnscriptUbuntufeisty*

References