Linuxfoundation Foomatic-Filters vulnerabilities

4 known vulnerabilities affecting linuxfoundation/foomatic-filters.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2011-2924MEDIUMCVSS 5.5≤ 4.0.122019-11-19
CVE-2011-2924 [MEDIUM] CWE-59 CVE-2011-2924: foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScr foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print f
nvd
CVE-2010-5325CRITICALCVSS 9.8≤ 4.0.52016-04-15
CVE-2010-5325 [CRITICAL] CWE-119 CVE-2010-5325: Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0. Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via a long job title.
nvd
CVE-2015-8560HIGHCVSS 7.3v4.0.0v4.0.1+16 more2016-04-14
CVE-2015-8560 [HIGH] CVE-2015-8560: Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.
nvd
CVE-2015-8327HIGHCVSS 7.5v4.0.0v4.0.1+16 more2015-12-17
CVE-2015-8327 [HIGH] CVE-2015-8327: Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
nvd