VYPR
Unrated severityNVD Advisory· Published Oct 23, 2008· Updated Apr 23, 2026

CVE-2008-3863

CVE-2008-3863

Description

Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes processing) option is enabled, allows user-assisted remote attackers to execute arbitrary code via a crafted ASCII file, related to the setfilename command.

Affected products

2
  • GNU/Enscript2 versions
    cpe:2.3:a:gnu:enscript:1.6.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:gnu:enscript:1.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:enscript:1.6.4:beta:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

32

News mentions

0

No linked articles in our index yet.