PT-2019-6659 · Linux Printing.Org · Foomatic-Rip
Tim Waugh
·
Published
2019-11-19
·
Updated
2020-08-18
·
CVE-2011-2924
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
foomatic-rip filter versions 4.0.12 and prior
Description
The issue allows a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter. This is possible because the foomatic-rip filter insecurely creates temporary files for storage of PostScript data when the debug mode is enabled.
Recommendations
For versions 4.0.12 and prior, consider disabling the debug mode as a temporary workaround to minimize the risk of exploitation. Restrict access to the foomatic-rip filter to minimize the risk of arbitrary file overwrites. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Foomatic-Rip