|
Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2005:033: enscript Vulnerability Scan
Vulnerability Scan Summary Check for the version of the enscript package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2005:033 (enscript).
A vulnerability in the enscript program's handling of the epsf command used to
insert inline EPS file into a document was found. A possible hacker could create a
carefully crafted ASCII file which would make used of the epsf pipe command in
such a way that it could execute arbitrary commands if the file was opened with
enscript (CVE-2004-1184).
Additionally, flaws were found in enscript that could be abused by executing
enscript with carefully crafted command-line arguments. These flaws only have a
security impact if enscript is executed by other programs and passed untrusted
data from remote users (CVE-2004-1185 and CVE-2004-1186).
The updated packages have been patched to prevent these problems.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:033
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|