Description: | Description:
The remote host is missing an update to enscript announced via advisory MDKSA-2005:033.
A vulnerability in the enscript program's handling of the epsf command used to insert inline EPS file into a document was found. An attacker could create a carefully crafted ASCII file which would make used of the epsf pipe command in such a way that it could execute arbitrary commands if the file was opened with enscript (CVE-2004-1184).
Additionally, flaws were found in enscript that could be abused by executing enscript with carefully crafted command-line arguments. These flaws only have a security impact if enscript is executed by other programs and passed untrusted data from remote users (CVE-2004-1185 and CVE-2004-1186).
The updated packages have been patched to prevent these problems.
Affected versions: 10.0, 10.1, Corporate 3.0, Corporate Server 2.1
Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.
http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2005:033 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1184 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1185 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1186
Risk factor : High
CVSS Score: 7.5
|