Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Ubuntu 12.04: USN-2831-2 Critical: Foomatic-Filters Remote Code Execution

Ubuntu Large Esm H500
foomatic-filters could be made to run programs as the lp user if it processed a specially crafted print job.
=========================================================================Ubuntu Security Notice USN-2831-2
December 07, 2015

foomatic-filters vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

foomatic-filters could be made to run programs as the lp user if it
processed a specially crafted print job.

Software Description:
- foomatic-filters: OpenPrinting printer support - filters

Details:

Michal Kowalczyk discovered that the foomatic-filters foomatic-rip filter
incorrectly stripped shell escape characters. A remote attacker could
possibly use this issue to execute arbitrary code as the lp user.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  foomatic-filters                4.0.16-0ubuntu0.3

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2831-2
  
  CVE-2015-8327

Package Information:
  https://launchpad.net/ubuntu/+source/foomatic-filters/4.0.16-0ubuntu0.3


Ubuntu 12.04: USN-2831-2 Critical: Foomatic-Filters Remote Code Execution

ubuntu
Calendar Grey December 7, 2015
Dist Ubuntu Esm H88
Ubuntu Security Notice USN-2930-1 details a CUPS vulnerability that could lead to unauthorized access.
foomatic-filters could be made to run programs as the lp user if it processed a specially crafted print job.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: foomatic-filters 4.0.16-0ubuntu0.3 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2831-2

CVE-2015-8327

Severity
critical
Lowest
Low
Medium
High
Critical

December 07, 2015

Package Information

https://launchpad.net/ubuntu/+source/foomatic-filters/4.0.16-0ubuntu0.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here