Candidate: CVE-2008-5078 PublicDate: 2008-12-19 17:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5078 https://bugzilla.redhat.com/show_bug.cgi?id=473958 Description: Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen.c) and (2) tilde_subst function (src/util.c) in GNU enscript 1.6.1, and possibly earlier, might allow remote attackers to execute arbitrary code via an epsf escape sequence with a long filename. Ubuntu-Description: Notes: mdeslaur> flaws do not affect enscript 1.6.4 as per redhat bug Bugs: Priority: untriaged Discovered-by: Assigned-to: CVSS: Patches_enscript: upstream_enscript: needs-triage dapper_enscript: not-affected gutsy_enscript: not-affected hardy_enscript: not-affected intrepid_enscript: not-affected devel_enscript: not-affected