Linux Foundation CUPS-Filters 1.0.66

CPE Details

Linux Foundation CUPS-Filters 1.0.66
1.0.66
2015-12-18
15h48 +00:00
2015-12-18
15h48 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:linuxfoundation:cups-filters:1.0.66:*:*:*:*:*:*:*

Informations

Vendor

linuxfoundation

Product

cups-filters

Version

1.0.66

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-24805 2023-05-17 17h33 +00:00 cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote code execution. `beh.c` contains the line `retval = system(cmdline) >> 8;` which calls the `system` command with the operand `cmdline`. `cmdline` contains multiple user controlled, unsanitized values. As a result an attacker with network access to the hosted print server can exploit this vulnerability to inject system commands which are executed in the context of the running server. This issue has been addressed in commit `8f2740357` and is expected to be bundled in the next release. Users are advised to upgrade when possible and to restrict access to network printers in the meantime.
8.8
Haute
CVE-2015-8560 2016-04-14 12h00 +00:00 Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.
7.3
Haute
CVE-2015-8327 2015-12-17 18h00 +00:00 Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
7.5
CVE-2015-3258 2015-07-14 14h00 +00:00 Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a small line size in a print job.
7.5
CVE-2015-3279 2015-07-14 14h00 +00:00 Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted line size in a print job, which triggers a heap-based buffer overflow.
7.5