CVE-2004-1185
CVE-2004-1185
Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://secunia.com/advisories/35074http://securitytracker.com/id?1012965https://exchange.xforce.ibmcloud.com/vulnerabilities/19029https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10808http://support.apple.com/kb/HT3549https://usn.ubuntu.com/68-1/http://www.debian.org/security/2005/dsa-654http://www.gentoo.org/security/en/glsa/glsa-200502-03.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:033http://www.redhat.com/support/errata/RHSA-2005-040.htmlhttp://www.securityfocus.com/archive/1/419768/100/0/threaded