Referenced CVEs:
CVE-2008-3863, CVE-2008-4306
Description:
===========================================================Ubuntu Security Notice USN-660-1 November 03, 2008enscript vulnerabilityCVE-2008-3863, CVE-2008-4306===========================================================A security issue affects the following Ubuntu releases:Ubuntu 6.06 LTSUbuntu 7.10Ubuntu 8.04 LTSUbuntu 8.10This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 6.06 LTS: enscript 1.6.4-7ubuntu0.2Ubuntu 7.10: enscript 1.6.4-11ubuntu0.2Ubuntu 8.04 LTS: enscript 1.6.4-12ubuntu0.8.04.1Ubuntu 8.10: enscript 1.6.4-12ubuntu0.8.10.1In general, a standard system upgrade is sufficient to effect thenecessary changes.Details follow:Ulf Härnhammar discovered multiple stack overflows in enscript's handling ofspecial escape arguments. If a user or automated system were tricked intoprocessing a malicious file with the "-e" option enabled, a remote attackercould execute arbitrary code or cause enscript to crash, possibly leadingto a denial of service.
More...