Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes processing) option is enabled, allows user-assisted remote attackers to execute arbitrary code via a crafted ASCII file, related to the setfilename command.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Enscript | — | Apply OS X security update 2009-002Upgrade macOS to the latest version | Dec 16, 2011 | Oct 23, 2008 |
| Centos_linux | — | Upgrade enscript | Dec 1, 2016 | Oct 23, 2008 |
| Debian | — | Upgrade enscript | Jul 30, 2024 | Oct 23, 2008 |
| Freebsd | — | Upgrade enscript-a4Upgrade enscript-letterdjUpgrade enscript-letter | Dec 10, 2025 | Nov 18, 2008 |
| Gentoo Linux | — | Upgrade app-text/enscript. | Oct 30, 2017 | Oct 23, 2008 |
| Oracle_linux | — | Upgrade enscript | Oct 16, 2024 | Oct 23, 2008 |
| Suse | — | Upgrade enscript | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade enscript | Nov 8, 2024 | Oct 23, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub