cbcvebase.
CVE-2011-2924
published 2019-11-19

CVE-2011-2924: foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was…

PriorityP428medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.43%
35.2th percentile
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianfoomatic-filters< foomatic-filters 4.0.12-1 (bookworm)foomatic-filters 4.0.12-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
foomatic-filtersfoomatic-filters
foomatic-filtersfoomatic-filters>= 0 < 4.0.12-14.0.12-1
foomatic-filtersfoomatic-filters>= 0 < 4.0.12-14.0.12-1
foomatic-filtersfoomatic-filters>= 0 < 4.0.12-14.0.12-1
foomatic-filtersfoomatic-filters>= 0 < 4.0.12-14.0.12-1
linuxfoundationfoomatic-filters<= 4.0.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.