Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8327

Опубликовано: 26 нояб. 2015
Источник: redhat
CVSS2: 5.1
EPSS Средний

Описание

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.

It was discovered that foomatic-rip failed to remove all shell special characters from inputs used to construct command lines for external programs run by the filter. An attacker could possibly use this flaw to execute arbitrary commands.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5cupsNot affected
Red Hat Enterprise Linux 6cupsNot affected
Red Hat Enterprise Linux 7cups-filtersNot affected
Red Hat Enterprise Linux 7foomaticWill not fix
Red Hat Enterprise Linux 6foomaticFixedRHSA-2016:049122.03.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1287523cups-filters: foomatic-rip did not consider the back tick as an illegal shell escape character

EPSS

Процентиль: 95%
0.1692
Средний

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 9 лет назад

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.

nvd
больше 9 лет назад

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.

debian
больше 9 лет назад

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-f ...

suse-cvrf
больше 9 лет назад

Security update for cups-filters

suse-cvrf
больше 9 лет назад

Security update for cups-filters

EPSS

Процентиль: 95%
0.1692
Средний

5.1 Medium

CVSS2