Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8560

Опубликовано: 12 дек. 2015
Источник: redhat
CVSS2: 5.1
EPSS Средний

Описание

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.

It was discovered that foomatic-rip failed to remove all shell special characters from inputs used to construct command lines for external programs run by the filter. An attacker could possibly use this flaw to execute arbitrary commands.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5cupsNot affected
Red Hat Enterprise Linux 6cupsNot affected
Red Hat Enterprise Linux 7cups-filtersNot affected
Red Hat Enterprise Linux 7foomaticWill not fix
Red Hat Enterprise Linux 6foomaticFixedRHSA-2016:049122.03.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1291227cups-filters: foomatic-rip did not consider semicolon as illegal shell escape character

EPSS

Процентиль: 93%
0.10031
Средний

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.3
ubuntu
почти 10 лет назад

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.

CVSS3: 7.3
nvd
почти 10 лет назад

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.

CVSS3: 7.3
debian
почти 10 лет назад

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-f ...

CVSS3: 7.3
github
больше 3 лет назад

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.

suse-cvrf
около 10 лет назад

Security update for foomatic-filters

EPSS

Процентиль: 93%
0.10031
Средний

5.1 Medium

CVSS2