CVE-2015-8327
high · 7.5Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
7.5
CVSS
10.2%
EPSS (exploit prob.)
95th
EPSS percentile
2015-12-17
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_hpc_node | 6.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server_eus | 6.7.z |
| redhat | enterprise_linux_workstation | 6.0 |
| linuxfoundation | foomatic-filters | 4.0.0 |
| linuxfoundation | foomatic-filters | 4.0.1 |
| linuxfoundation | foomatic-filters | 4.0.2 |
| linuxfoundation | foomatic-filters | 4.0.3 |
| linuxfoundation | foomatic-filters | 4.0.4 |
| linuxfoundation | foomatic-filters | 4.0.5 |
| linuxfoundation | foomatic-filters | 4.0.6 |
| linuxfoundation | foomatic-filters | 4.0.7 |
| linuxfoundation | foomatic-filters | 4.0.8 |
| linuxfoundation | foomatic-filters | 4.0.9 |
| linuxfoundation | foomatic-filters | 4.0.10 |
| linuxfoundation | foomatic-filters | 4.0.11 |
| linuxfoundation | foomatic-filters | 4.0.12 |
| linuxfoundation | foomatic-filters | 4.0.13 |
| linuxfoundation | foomatic-filters | 4.0.14 |
| linuxfoundation | foomatic-filters | 4.0.15 |
| linuxfoundation | foomatic-filters | 4.0.16 |
| linuxfoundation | foomatic-filters | 4.0.17 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 15.04 |
| canonical | ubuntu_linux | 15.10 |
| linuxfoundation | cups-filters | 1.0.42 |
| linuxfoundation | cups-filters | 1.0.43 |
| linuxfoundation | cups-filters | 1.0.44 |
| linuxfoundation | cups-filters | 1.0.45 |
| linuxfoundation | cups-filters | 1.0.46 |
| linuxfoundation | cups-filters | 1.0.47 |
| linuxfoundation | cups-filters | 1.0.48 |
| linuxfoundation | cups-filters | 1.0.49 |
| linuxfoundation | cups-filters | 1.0.50 |
| linuxfoundation | cups-filters | 1.0.51 |
| linuxfoundation | cups-filters | 1.0.52 |
| linuxfoundation | cups-filters | 1.0.53 |
| linuxfoundation | cups-filters | 1.0.54 |
Check a specific version with /api/v1/cve/match.
References
- http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/annotate/head:/NEWS
- http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7406
- http://lists.opensuse.org/opensuse-updates/2016-01/msg00065.html
- http://rhn.redhat.com/errata/RHSA-2016-0491.html
- http://www.debian.org/security/2015/dsa-3411
- http://www.debian.org/security/2015/dsa-3429
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.securityfocus.com/bid/78524
- http://www.ubuntu.com/usn/USN-2831-1
- http://www.ubuntu.com/usn/USN-2831-2
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=806886
- https://lists.debian.org/debian-printing/2015/11/msg00020.html
- https://lists.debian.org/debian-printing/2015/12/msg00001.html
- http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/annotate/head:/NEWS
- http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7406
- http://lists.opensuse.org/opensuse-updates/2016-01/msg00065.html
- http://rhn.redhat.com/errata/RHSA-2016-0491.html
- http://www.debian.org/security/2015/dsa-3411
- http://www.debian.org/security/2015/dsa-3429
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.securityfocus.com/bid/78524
- http://www.ubuntu.com/usn/USN-2831-1
- http://www.ubuntu.com/usn/USN-2831-2
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=806886
- https://lists.debian.org/debian-printing/2015/11/msg00020.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-8327