Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8560

Опубликовано: 12 дек. 2015
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.

It was discovered that foomatic-rip failed to remove all shell special characters from inputs used to construct command lines for external programs run by the filter. An attacker could possibly use this flaw to execute arbitrary commands.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5cupsNot affected
Red Hat Enterprise Linux 6cupsNot affected
Red Hat Enterprise Linux 7cups-filtersNot affected
Red Hat Enterprise Linux 7foomaticWill not fix
Red Hat Enterprise Linux 6foomaticFixedRHSA-2016:049122.03.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1291227cups-filters: foomatic-rip did not consider semicolon as illegal shell escape character

EPSS

Процентиль: 92%
0.08557
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 9 лет назад

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.

CVSS3: 7.3
nvd
больше 9 лет назад

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.

CVSS3: 7.3
debian
больше 9 лет назад

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-f ...

CVSS3: 7.3
github
больше 3 лет назад

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.

suse-cvrf
больше 9 лет назад

Security update for foomatic-filters

EPSS

Процентиль: 92%
0.08557
Низкий

5.1 Medium

CVSS2

Уязвимость CVE-2015-8560