Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

SciLinux: SLSA-2016:0491-1 Moderate: Foomatic Memory Issues and Threats

Scientific Large Esm H500
Moderate: foomatic security update
Date: Wed, 23 Mar 2016 16:29:52 -0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Subject: Security ERRATA Moderate: foomatic on SL6.x i386/x86_64
MIME-Version: 1.0
Message-ID: <20160323162952.22519.65383@slpackages.fnal.gov>

Synopsis: Moderate: foomatic security update
Advisory ID: SLSA-2016:0491-1
Issue Date: 2016-03-23
CVE Numbers: CVE-2010-5325
 CVE-2015-8327
 CVE-2015-8560
--

It was discovered that the unhtmlify() function of foomatic-rip did not
correctly calculate buffer sizes, possibly leading to a heap-based memory
corruption. A malicious attacker could exploit this flaw to cause
foomatic-rip to crash or, possibly, execute arbitrary code.
(CVE-2010-5325)

It was discovered that foomatic-rip failed to remove all shell special
characters from inputs used to construct command lines for external
programs run by the filter. An attacker could possibly use this flaw to
execute arbitrary commands. (CVE-2015-8327, CVE-2015-8560)
--

SL6
 x86_64
 foomatic-4.0.4-5.el6_7.x86_64.rpm
 foomatic-debuginfo-4.0.4-5.el6_7.x86_64.rpm
 i386
 foomatic-4.0.4-5.el6_7.i686.rpm
 foomatic-debuginfo-4.0.4-5.el6_7.i686.rpm

- Scientific Linux Development Team

Related News

Your message here