[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-1184Date: (C)2005-01-21   (M)2023-12-22


The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.6
Exploit Score: 3.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1012965
BID-12329
http://www.securityfocus.com/archive/1/435199/100/0/threaded
SECUNIA-35074
ADV-2009-1297
APPLE-SA-2009-05-12
DSA-654
FLSA:152892
GLSA-200502-03
MDKSA-2005:033
RHSA-2005:040
TA09-133A
USN-68-1
enscript-epsf-command-ececution(19012)
http://support.apple.com/kb/HT3549
oval:org.mitre.oval:def:9658

CPE    37
cpe:/o:suse:suse_linux:9.2
cpe:/o:suse:suse_linux:7.2
cpe:/o:suse:suse_linux:9.0
cpe:/o:suse:suse_linux:7.3
...

© SecPod Technologies