PT-2011-1138 · Linux Printing+2 · Foomatic-Filters+2
Published
2011-07-29
·
Updated
2024-06-15
·
CVE-2011-2697
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
foomatic-filters versions prior to 4.0.9
foomatic-3.0.2
HPLIP version 3.11.5
Description
The issue affects the foomatic-filters package and HPLIP, allowing remote attackers to execute arbitrary code via a crafted
FoomaticRIPCommandLine field in a .ppd file, potentially leading to a breach of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.Recommendations
For foomatic-filters versions prior to 4.0.9, update to version 4.0.9 or later.
For foomatic-3.0.2, consider disabling the vulnerable package until a patch is available.
For HPLIP version 3.11.5, avoid using the
FoomaticRIPCommandLine field in .ppd files until the issue is resolved.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hplip
Red Hat
Foomatic-Filters