Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 11.04 USN-1194-1 Medium: Foomatic Filters Remote Code Execution

ubuntu
Calendar Grey August 22, 2011
Scroller Ubuntu
A potential vulnerability exists within CUPS filters on Ubuntu, allowing an attacker to run any program under the "lp" user. Discover the details.
An attacker could send crafted input to Foomatic and cause it to run programs as the "lp" user.

Summary

An attacker could send crafted input to Foomatic and cause it to run

programs as the "lp" user.

Software Description:

- foomatic-filters: OpenPrinting printer support - filters

Details:

It was discovered that the foomatic-rip Foomatic filter incorrectly

handled command-line options. An attacker could use this flaw to cause

Foomatic to execute arbitrary code as the "lp" user.

In the default installation, attackers would be isolated by the CUPS

AppArmor profile.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  foomatic-filters                4.0.7-0ubuntu1.1

Ubuntu 10.10:
  foomatic-filters                4.0.5-0ubuntu3.1

Ubuntu 10.04 LTS:
  foomatic-filters                4.0.4-0ubuntu1.1

Ubuntu 8.04 LTS:
  foomatic-filters                3.0.2-20071204-0ubuntu2.3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1194-1

CVE-2011-2697, CVE-2011-2964

Severity
medium
Lowest
Low
Medium
High
Critical

August 22, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.