CVE-2015-8327
published 2015-12-17CVE-2015-8327: Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote…
PriorityP355high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
10.17%
95.1th percentile
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
Affected
82 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | cups-filters | < cups-filters 1.4.0-1 (bookworm) | cups-filters 1.4.0-1 (bookworm) |
| debian | cups-filters | < cups-filters 1.2.0-1 (bookworm) | cups-filters 1.2.0-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | foomatic-filters | < cups-filters 1.4.0-1 (bookworm) | cups-filters 1.4.0-1 (bookworm) |
| debian | foomatic-filters | < cups-filters 1.2.0-1 (bookworm) | cups-filters 1.2.0-1 (bookworm) |
| foomatic-filters | foomatic-filters | >= 0 < 4.0.17-7 | 4.0.17-7 |
| foomatic-filters | foomatic-filters | >= 0 < 4.0.17-7 | 4.0.17-7 |
| foomatic-filters | foomatic-filters | >= 0 < 4.0.17-7 | 4.0.17-7 |
| foomatic-filters | foomatic-filters | >= 0 < 4.0.17-7 | 4.0.17-7 |
| linuxfoundation | cups-filters | — | — |
| linuxfoundation | cups-filters | — | — |
| linuxfoundation | cups-filters | — | — |
| linuxfoundation | cups-filters | — | — |
| linuxfoundation | cups-filters | — | — |
| linuxfoundation | cups-filters | — | — |
| linuxfoundation | cups-filters | — | — |
| linuxfoundation | cups-filters | — | — |
| linuxfoundation | cups-filters | — | — |
| linuxfoundation | cups-filters | — | — |
| linuxfoundation | cups-filters | — | — |
| linuxfoundation | cups-filters | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cups-filters: foomatic-rip did not consider semicolon as illegal shell escape character
vendor_redhat·2015-12-12·CVSS 7.5
CVE-2015-8560 [HIGH] CWE-77 cups-filters: foomatic-rip did not consider semicolon as illegal shell escape character
cups-filters: foomatic-rip did not consider semicolon as illegal shell escape character
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.
It was discovered that foomatic-rip failed to remove all shell special characters from inputs used to construct command lines for external programs run by the filter. An attacker could possibly use this flaw to execute arbitrary commands.
Package: cups (Red Hat Enterprise Linux 5) - Not affected
Package: cups (Red Hat Enterprise Linux 6) - Not affected
Package: cups-filters (Red Hat Enterprise Linux 7) - Not affected
Ubuntu
cups-filters vulnerability
vendor_ubuntu·2015-12-07
CVE-2015-8327 cups-filters vulnerability
Title: cups-filters vulnerability
Summary: cups-filters could be made to run programs as the lp user if it processed a
specially crafted print job.
Michal Kowalczyk discovered that the cups-filters foomatic-rip filter
incorrectly stripped shell escape characters. A remote attacker could
possibly use this issue to execute arbitrary code as the lp user.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
foomatic-filters vulnerability
vendor_ubuntu·2015-12-07
CVE-2015-8327 foomatic-filters vulnerability
Title: foomatic-filters vulnerability
Summary: foomatic-filters could be made to run programs as the lp user if it
processed a specially crafted print job.
Michal Kowalczyk discovered that the foomatic-filters foomatic-rip filter
incorrectly stripped shell escape characters. A remote attacker could
possibly use this issue to execute arbitrary code as the lp user.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cups-filters: foomatic-rip did not consider the back tick as an illegal shell escape character
vendor_redhat·2015-11-26·CVSS 7.5
CVE-2015-8327 [HIGH] CWE-77 cups-filters: foomatic-rip did not consider the back tick as an illegal shell escape character
cups-filters: foomatic-rip did not consider the back tick as an illegal shell escape character
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
It was discovered that foomatic-rip failed to remove all shell special characters from inputs used to construct command lines for external programs run by the filter. An attacker could possibly use this flaw to execute arbitrary commands.
Package: cups (Red Hat Enterprise Linux 5) - Not affected
Package: cups (Red Hat Enterprise Linux 6) - Not affected
Package: cups-filters (Red Hat Enterprise Linux 7) - Not affected
Package: foomatic (Red Hat Enterprise Lin
Debian
CVE-2015-8560: cups-filters - Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0...
vendor_debian·2015·CVSS 7.5
CVE-2015-8560 [HIGH] CVE-2015-8560: cups-filters - Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0...
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.
Scope: local
bookworm: resolved (fixed in 1.4.0-1)
bullseye: resolved (fixed in 1.4.0-1)
forky: resolved (fixed in 1.4.0-1)
sid: resolved (fixed in 1.4.0-1)
trixie: resolved (fixed in 1.4.0-1)
Debian
CVE-2015-8327: cups-filters - Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0...
vendor_debian·2015·CVSS 7.5
CVE-2015-8327 [HIGH] CVE-2015-8327: cups-filters - Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0...
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
Scope: local
bookworm: resolved (fixed in 1.2.0-1)
bullseye: resolved (fixed in 1.2.0-1)
forky: resolved (fixed in 1.2.0-1)
sid: resolved (fixed in 1.2.0-1)
trixie: resolved (fixed in 1.2.0-1)
GHSA
GHSA-cfgh-jg4g-q29h: Incomplete blacklist vulnerability in util
ghsa_unreviewed·2022-05-14
CVE-2015-8327 [HIGH] GHSA-cfgh-jg4g-q29h: Incomplete blacklist vulnerability in util
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
GHSA
GHSA-rcfc-82wc-2wjm: Incomplete blacklist vulnerability in util
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2015-8560 [HIGH] GHSA-rcfc-82wc-2wjm: Incomplete blacklist vulnerability in util
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.
OSV
CVE-2015-8560: Incomplete blacklist vulnerability in util
osv·2016-04-14·CVSS 7.5
CVE-2015-8560 [HIGH] CVE-2015-8560: Incomplete blacklist vulnerability in util
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.
OSV
CVE-2015-8327: Incomplete blacklist vulnerability in util
osv·2015-12-17·CVSS 7.5
CVE-2015-8327 [HIGH] CVE-2015-8327: Incomplete blacklist vulnerability in util
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8560 cups-filters: foomatic-rip did not consider semicolon as illegal shell escape character
bugzilla·2015-12-14·CVSS 7.5
CVE-2015-8560 [HIGH] CVE-2015-8560 cups-filters: foomatic-rip did not consider semicolon as illegal shell escape character
CVE-2015-8560 cups-filters: foomatic-rip did not consider semicolon as illegal shell escape character
Following security fix was released in v1.4.0:
- foomatic-rip: SECURITY FIX: Also consider the semicolon (';') as an illegal shell escape character. Thanks to Adam Chester (adam dot chester at pentest dot co dot uk) for the hint.
Upstream patch:
http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7419
CVE request:
http://seclists.org/oss-sec/2015/q4/479
Discussion:
Created foomatic tracking bugs for this issue:
Affects: fedora-all [bug 1291229]
---
Created cups-filters tracking bugs for this issue:
Affects: fedora-all [bug 1291228]
---
In terms of affected products and components (with respect to foomatic-filters packaged in cups-fitlers or foomatic p
Bugzilla
CVE-2015-8327 cups-filters: foomatic-rip did not consider the back tick as an illegal shell escape character
bugzilla·2015-12-02·CVSS 7.5
CVE-2015-8327 [HIGH] CVE-2015-8327 cups-filters: foomatic-rip did not consider the back tick as an illegal shell escape character
CVE-2015-8327 cups-filters: foomatic-rip did not consider the back tick as an illegal shell escape character
The following issue was fixed in the 1.2.0 release of cups-filters:
foomatic-rip: SECURITY FIX: Also consider the back tick ('`') as an illegal shell escape character. Thanks to Michal Kowalczyk from the Google Security Team for the hint (CVE-2015-8327).
External References:
https://lists.debian.org/debian-printing/2015/11/msg00020.html
Discussion:
Fixed in Fedora in:
cups-filters-1.2.0-1.fc24
cups-filters-1.2.0-1.fc23
cups-filters-1.2.0-1.fc22
---
Upstream fix apparently is:
http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7406
Plus a related change to add CVE to the NEWS file:
http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filte
http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/annotate/head:/NEWShttp://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7406http://lists.opensuse.org/opensuse-updates/2016-01/msg00065.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0491.htmlhttp://www.debian.org/security/2015/dsa-3411http://www.debian.org/security/2015/dsa-3429http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/bid/78524http://www.ubuntu.com/usn/USN-2831-1http://www.ubuntu.com/usn/USN-2831-2https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=806886https://lists.debian.org/debian-printing/2015/11/msg00020.htmlhttps://lists.debian.org/debian-printing/2015/12/msg00001.htmlhttp://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/annotate/head:/NEWShttp://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7406http://lists.opensuse.org/opensuse-updates/2016-01/msg00065.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0491.htmlhttp://www.debian.org/security/2015/dsa-3411http://www.debian.org/security/2015/dsa-3429http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/bid/78524http://www.ubuntu.com/usn/USN-2831-1http://www.ubuntu.com/usn/USN-2831-2https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=806886https://lists.debian.org/debian-printing/2015/11/msg00020.htmlhttps://lists.debian.org/debian-printing/2015/12/msg00001.html
2015-12-17
Published