﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
1799	Enscript security fixes	alexander@…	Randy McMurchy	"Unpatched Enscript is vulnerable to:

CAN-2004-1184: Enscript does not sanitize filenames, which allows remote
attackers or local users to execute arbitrary commands via crafted filenames.

CAN-2004-1185: The EPSF pipe support in Enscript allows remote attackers or
local users to execute arbitrary commands via shell metacharacters.

CAN-2004-1186: Multiple buffer overflows in Enscript allow remote attackers or
local users to cause a denial of service (application crash).

Here ""remote attackers"" = people who feed untrusted data to Enscript exposed via
a web form or a similar mechanism."	defect	closed	low	6.2.0	BOOK	SVN	low	fixed	Enscript	
