Unrated severityNVD Advisory· Published Jan 21, 2005· Updated Apr 16, 2026
CVE-2004-1185
CVE-2004-1185
Description
Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.
Affected products
7cpe:2.3:a:gnu:enscript:1.3.0:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:gnu:enscript:1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:enscript:1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:enscript:1.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:enscript:1.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:enscript:1.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:enscript:1.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:enscript:1.6.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
16- www.debian.org/security/2005/dsa-654nvdPatchVendor Advisory
- www.gentoo.org/security/en/glsa/glsa-200502-03.xmlnvdPatch
- www.us-cert.gov/cas/techalerts/TA09-133A.htmlnvdUS Government Resource
- lists.apple.com/archives/security-announce/2009/May/msg00002.htmlnvd
- secunia.com/advisories/35074nvd
- securitytracker.com/idnvd
- support.apple.com/kb/HT3549nvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2005-040.htmlnvd
- www.securityfocus.com/archive/1/419768/100/0/threadednvd
- www.securityfocus.com/archive/1/435199/100/0/threadednvd
- www.securityfocus.com/bid/12329nvd
- www.vupen.com/english/advisories/2009/1297nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/19029nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10808nvd
- usn.ubuntu.com/68-1/nvd
News mentions
0No linked articles in our index yet.