Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_linux_desktop | Redhat | 6.0 (including) | 6.0 (including) |
Enterprise_linux_hpc_node | Redhat | 6.0 (including) | 6.0 (including) |
Enterprise_linux_server | Redhat | 6.0 (including) | 6.0 (including) |
Enterprise_linux_server_eus | Redhat | 6.7.z (including) | 6.7.z (including) |
Enterprise_linux_workstation | Redhat | 6.0 (including) | 6.0 (including) |
Cups-filters | Ubuntu | trusty | * |
Cups-filters | Ubuntu | upstream | * |
Cups-filters | Ubuntu | vivid | * |
Cups-filters | Ubuntu | wily | * |
Foomatic-filters | Ubuntu | precise | * |
Foomatic-filters | Ubuntu | trusty | * |
Foomatic-filters | Ubuntu | upstream | * |
Foomatic-filters | Ubuntu | vivid | * |
Foomatic-filters | Ubuntu | wily | * |
Red Hat Enterprise Linux 6 | RedHat | foomatic-0:4.0.4-5.el6_7 | * |