Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8327

Опубликовано: 26 нояб. 2015
Источник: redhat
CVSS2: 5.1
EPSS Средний

Описание

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.

It was discovered that foomatic-rip failed to remove all shell special characters from inputs used to construct command lines for external programs run by the filter. An attacker could possibly use this flaw to execute arbitrary commands.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5cupsNot affected
Red Hat Enterprise Linux 6cupsNot affected
Red Hat Enterprise Linux 7cups-filtersNot affected
Red Hat Enterprise Linux 7foomaticWill not fix
Red Hat Enterprise Linux 6foomaticFixedRHSA-2016:049122.03.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1287523cups-filters: foomatic-rip did not consider the back tick as an illegal shell escape character

EPSS

Процентиль: 95%
0.2071
Средний

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 10 лет назад

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.

nvd
почти 10 лет назад

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.

debian
почти 10 лет назад

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-f ...

suse-cvrf
почти 10 лет назад

Security update for cups-filters

suse-cvrf
почти 10 лет назад

Security update for cups-filters

EPSS

Процентиль: 95%
0.2071
Средний

5.1 Medium

CVSS2