<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
	<DocumentTitle xml:lang="en">An update for enscript is now available for openEuler-22.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-24.03-LTS,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS-SP1</DocumentTitle>
	<DocumentType>Security Advisory</DocumentType>
	<DocumentPublisher Type="Vendor">
		<ContactDetails>openeuler-security@openeuler.org</ContactDetails>
		<IssuingAuthority>openEuler security committee</IssuingAuthority>
	</DocumentPublisher>
	<DocumentTracking>
		<Identification>
			<ID>openEuler-SA-2025-1051</ID>
		</Identification>
		<Status>Final</Status>
		<Version>1.0</Version>
		<RevisionHistory>
			<Revision>
				<Number>1.0</Number>
				<Date>2025-01-17</Date>
				<Description>Initial</Description>
			</Revision>
		</RevisionHistory>
		<InitialReleaseDate>2025-01-17</InitialReleaseDate>
		<CurrentReleaseDate>2025-01-17</CurrentReleaseDate>
		<Generator>
			<Engine>openEuler SA Tool V1.0</Engine>
			<Date>2025-01-17</Date>
		</Generator>
	</DocumentTracking>
	<DocumentNotes>
		<Note Title="Synopsis" Type="General" Ordinal="1" xml:lang="en">enscript security update</Note>
		<Note Title="Summary" Type="General" Ordinal="2" xml:lang="en">An update for enscript is now available for openEuler-22.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-24.03-LTS,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS-SP1</Note>
		<Note Title="Description" Type="General" Ordinal="3" xml:lang="en">GNU enscript is a computer program that converts text files to PostScript, RTF, or HTML formats. If no input files are given, enscript processes standard input. Enscript can be extended to handle different output media and it has many options which can be used to customize print-outs.

Security Fix(es):

(CVE-2018-17942)</Note>
		<Note Title="Topic" Type="General" Ordinal="4" xml:lang="en">An update for enscript is now available for openEuler-22.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-24.03-LTS,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS-SP1.

openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.</Note>
		<Note Title="Severity" Type="General" Ordinal="5" xml:lang="en">High</Note>
		<Note Title="Affected Component" Type="General" Ordinal="6" xml:lang="en">enscript</Note>
	</DocumentNotes>
	<DocumentReferences>
		<Reference Type="Self">
			<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1051</URL>
		</Reference>
		<Reference Type="openEuler CVE">
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2018-17942</URL>
		</Reference>
		<Reference Type="Other">
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2018-17942</URL>
		</Reference>
	</DocumentReferences>
	<ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
		<Branch Type="Product Name" Name="openEuler">
			<FullProductName ProductID="openEuler-22.03-LTS-SP3" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP3">openEuler-22.03-LTS-SP3</FullProductName>
			<FullProductName ProductID="openEuler-20.03-LTS-SP4" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">openEuler-20.03-LTS-SP4</FullProductName>
			<FullProductName ProductID="openEuler-24.03-LTS" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">openEuler-24.03-LTS</FullProductName>
			<FullProductName ProductID="openEuler-22.03-LTS-SP4" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">openEuler-22.03-LTS-SP4</FullProductName>
			<FullProductName ProductID="openEuler-24.03-LTS-SP1" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">openEuler-24.03-LTS-SP1</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="aarch64">
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP3">enscript-1.6.6-22.oe2203sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debuginfo-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP3">enscript-debuginfo-1.6.6-22.oe2203sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debugsource-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP3">enscript-debugsource-1.6.6-22.oe2203sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-help-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP3">enscript-help-1.6.6-22.oe2203sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">enscript-1.6.6-22.oe2003sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debuginfo-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">enscript-debuginfo-1.6.6-22.oe2003sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debugsource-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">enscript-debugsource-1.6.6-22.oe2003sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-help-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">enscript-help-1.6.6-22.oe2003sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">enscript-1.6.6-22.oe2403.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debuginfo-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">enscript-debuginfo-1.6.6-22.oe2403.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debugsource-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">enscript-debugsource-1.6.6-22.oe2403.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-help-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">enscript-help-1.6.6-22.oe2403.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">enscript-1.6.6-22.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debuginfo-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">enscript-debuginfo-1.6.6-22.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debugsource-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">enscript-debugsource-1.6.6-22.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-help-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">enscript-help-1.6.6-22.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">enscript-1.6.6-22.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debuginfo-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">enscript-debuginfo-1.6.6-22.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debugsource-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">enscript-debugsource-1.6.6-22.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="enscript-help-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">enscript-help-1.6.6-22.oe2403sp1.aarch64.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="src">
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP3">enscript-1.6.6-22.oe2203sp3.src.rpm</FullProductName>
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">enscript-1.6.6-22.oe2003sp4.src.rpm</FullProductName>
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">enscript-1.6.6-22.oe2403.src.rpm</FullProductName>
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">enscript-1.6.6-22.oe2203sp4.src.rpm</FullProductName>
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">enscript-1.6.6-22.oe2403sp1.src.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="x86_64">
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP3">enscript-1.6.6-22.oe2203sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debuginfo-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP3">enscript-debuginfo-1.6.6-22.oe2203sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debugsource-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP3">enscript-debugsource-1.6.6-22.oe2203sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-help-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP3">enscript-help-1.6.6-22.oe2203sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">enscript-1.6.6-22.oe2003sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debuginfo-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">enscript-debuginfo-1.6.6-22.oe2003sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debugsource-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">enscript-debugsource-1.6.6-22.oe2003sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-help-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">enscript-help-1.6.6-22.oe2003sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">enscript-1.6.6-22.oe2403.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debuginfo-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">enscript-debuginfo-1.6.6-22.oe2403.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debugsource-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">enscript-debugsource-1.6.6-22.oe2403.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-help-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">enscript-help-1.6.6-22.oe2403.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">enscript-1.6.6-22.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debuginfo-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">enscript-debuginfo-1.6.6-22.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debugsource-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">enscript-debugsource-1.6.6-22.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-help-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">enscript-help-1.6.6-22.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">enscript-1.6.6-22.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debuginfo-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">enscript-debuginfo-1.6.6-22.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-debugsource-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">enscript-debugsource-1.6.6-22.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="enscript-help-1.6.6-22" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">enscript-help-1.6.6-22.oe2403sp1.x86_64.rpm</FullProductName>
		</Branch>
	</ProductTree>
	<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a trailing &apos;\0&apos; character during %f processing.</Note>
		</Notes>
		<ReleaseDate>2025-01-17</ReleaseDate>
		<CVE>CVE-2018-17942</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-22.03-LTS-SP3</ProductID>
				<ProductID>openEuler-20.03-LTS-SP4</ProductID>
				<ProductID>openEuler-24.03-LTS</ProductID>
				<ProductID>openEuler-22.03-LTS-SP4</ProductID>
				<ProductID>openEuler-24.03-LTS-SP1</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>High</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>8.8</BaseScore>
				<Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>enscript security update</Description>
				<DATE>2025-01-17</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1051</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
</cvrfdoc>