PT-2011-1139 · Openprinting+1 · Foomatic+1
Publicado
2011-07-29
·
Atualizado
2017-08-29
·
CVE-2011-2964
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Foomatic versions prior to 4.0.9
Foomatic version 4.0.6
Foomatic version 4.0.4
Description
The issue allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPCommandLine field in a .ppd file. Exploitation of the vulnerabilities may lead to disruption of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations
For Foomatic versions prior to 4.0.9, update to version 4.0.9 or later.
For Foomatic version 4.0.6, update to version 4.0.9 or later.
For Foomatic version 4.0.4, update to version 4.0.9 or later.
As a temporary workaround, consider restricting access to the
foomaticrip.c file and the *FoomaticRIPCommandLine field in .ppd files until a patch is available.Exploit
Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Foomatic
Red Hat