Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Enterprise_linux_desktop | Redhat | 6.0 (including) | 6.0 (including) |
| Enterprise_linux_hpc_node | Redhat | 6.0 (including) | 6.0 (including) |
| Enterprise_linux_server | Redhat | 6.0 (including) | 6.0 (including) |
| Enterprise_linux_server_eus | Redhat | 6.7.z (including) | 6.7.z (including) |
| Enterprise_linux_workstation | Redhat | 6.0 (including) | 6.0 (including) |
| Red Hat Enterprise Linux 6 | RedHat | foomatic-0:4.0.4-5.el6_7 | * |
| Cups-filters | Ubuntu | trusty | * |
| Cups-filters | Ubuntu | upstream | * |
| Cups-filters | Ubuntu | vivid | * |
| Cups-filters | Ubuntu | wily | * |
| Foomatic-filters | Ubuntu | precise | * |
| Foomatic-filters | Ubuntu | trusty | * |
| Foomatic-filters | Ubuntu | upstream | * |
| Foomatic-filters | Ubuntu | vivid | * |
| Foomatic-filters | Ubuntu | wily | * |