Executive Summary
| Summary | |
|---|---|
| Title | foomatic-filters: User-assisted execution of arbitrary code |
| Informations | |||
|---|---|---|---|
| Name | GLSA-201203-07 | First vendor Publication | 2012-03-06 |
| Vendor | Gentoo | Last vendor Modification | 2012-03-06 |
| Severity (Vendor) | Normal | Revision | N/A |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 6.8 | Attack Range | Network |
| Cvss Impact Score | 6.4 | Attack Complexity | Medium |
| Cvss Expoit Score | 8.6 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Synopsis A vulnerability in foomatic-filters could result in the execution of arbitrary code. Background The foomatic-filters package contains wrapper scripts which are designed to be used with Foomatic. Description The foomatic-rip filter improperly handles command-line arguments, including those issued by FoomaticRIPCommandLine fields in PPD files. Impact A remote attacker could entice a user to open a specially crafted PPD file, possibly resulting in execution of arbitrary code with the privileges of the system user "lp". Workaround There is no known workaround at this time. Resolution All foomatic-filters users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=net-print/foomatic-filters-4.0.9" References [ 1 ] CVE-2011-2697 : http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2697 [ 2 ] CVE-2011-2964 : http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2964 Availability This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201203-07.xml |
Original Source
| Url : http://security.gentoo.org/glsa/glsa-201203-07.xml |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-94 | Failure to Control Generation of Code ('Code Injection') |
| CWE-20 | Improper Input Validation |
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Application | 1 | |
| Application | 1 |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 74206 | Foomatic foomatic-filters foomatic-rip foomaticrip.c PPD File *FoomaticRIPCom... |
| 74205 | HP Linux Imaging and Printing (HPLIP) foomatic-rip-hplip PPD File *FoomaticRI... |

GLSA-201203-07
(Medium)





