Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2011-2924
Disclosure Date: November 19, 2019 (last updated November 27, 2024)
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter.
0
Attacker Value
Unknown
CVE-2011-2923
Disclosure Date: November 19, 2019 (last updated November 27, 2024)
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter.
0
Attacker Value
Unknown
CVE-2010-5325
Disclosure Date: April 15, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via a long job title.
0
Attacker Value
Unknown
CVE-2015-8560
Disclosure Date: April 14, 2016 (last updated November 25, 2024)
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.
0
Attacker Value
Unknown
CVE-2015-8327
Disclosure Date: December 17, 2015 (last updated October 05, 2023)
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
0
Attacker Value
Unknown
CVE-2004-0801
Disclosure Date: September 16, 2004 (last updated February 22, 2025)
Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.
0