-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ## ## Patch description of patch 710731c2084694b924777e34da67a64c ## Kind: security Shortdescription.english: Security update for enscript Longdescription.english: Applies to Package: enscript Product(s): Release: 20050211 Obsoletes: none Indications Everyone using enscript should update. Contraindications None. Problem description * Unsanitised input can caues the execution of arbitrary commands via EPSF pipe support. This has been disabled, also upstream ( CAN-2004-1184). * Due to missing sanitising of filenames it is possible that a specially crafted filename can cause arbitrary commands to be executed ( CAN-2004-1185). * Multiple buffer overflows can cause the program to crash ( CAN-2004-1186). Solution Please install the updates provided at the location noted below. Installation notes This update is provided as an RPM package that can easily be installed onto a running system by using this command: rpm -Fvh enscript.rpm Hsilgne.noitpircsedgnol: Size: 285 MinYaST1Version: MinYaST2Version: UpdateOnlyInstalled: true Packages: ## ## -----> enscript <----- ## Filename: enscript.rpm Label: ASCII to PostScript(tm) converter Series: i586 Size: 1266020 292577 PatchRpmBasedOn: 1.6.2-543 PatchRpmSize: 1266020 118936 Buildtime: 1108034444 DepAND: DepOR: DepExcl: Flag: Category: RpmGroup: Productivity/Publishing/PS Copyright: GPL AuthorName: Markku Rossi AuthorAddress: Version: 1.6.2-822 StartCommand: Obsoletes: Requires: /bin/sh /usr/bin/perl ld-linux.so.2 libc.so.6 libc.so.6(GLIBC_2.0) libc.so.6(GLIBC_2.1) libm.so.6 rpmlib(PayloadIsBzip2) <= 3.0.5-1 Provides: enscript genscript nenscrip Segakcap: -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQFCENNyqE7a6JyACsoRAlg6AJ0QUQv/q0dWp2YyCoT917S7DMoO8gCd FQpoeT5JHp6p2JaKrDXNysq9Qag= =efH/ -----END PGP SIGNATURE-----