Foomatic 'foomatic-rip' Command Injection Vulnerability
BID:48674
Info
Foomatic 'foomatic-rip' Command Injection Vulnerability
| Bugtraq ID: | 48674 |
| Class: | Design Error |
| CVE: |
CVE-2011-2697 CVE-2011-2964 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2011 12:00AM |
| Updated: | Apr 16 2015 05:43PM |
| Credit: | Sebastian Krahmer |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 73.C0.41 Xerox FreeFlow Print Server (FFPS) 73.B3.61 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 11.04 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop version 4 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 LinuxFoundation.org Foomatic 4.0.6 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Avaya Proactive Contact 5.0 Avaya Proactive Contact 4.2.2 Avaya Proactive Contact 4.2.1 Avaya Proactive Contact 4.2 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 |
| Not Vulnerable: | |
Discussion
Foomatic 'foomatic-rip' Command Injection Vulnerability
Foomatic is prone to a command-injection vulnerability.
Attackers can leverage this issue to run arbitrary commands with 'lp-user' privileges.
Foomatic 4.0.6 is vulnerable; other versions may also be affected.
Foomatic is prone to a command-injection vulnerability.
Attackers can leverage this issue to run arbitrary commands with 'lp-user' privileges.
Foomatic 4.0.6 is vulnerable; other versions may also be affected.
Exploit / POC
Foomatic 'foomatic-rip' Command Injection Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Foomatic 'foomatic-rip' Command Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2010.1 x86_64
Mandriva Linux Mandrake 2010.1
Mandriva Linux Mandrake 2009.0
MandrakeSoft Corporate Server 4.0
Mandriva Linux Mandrake 2009.0 x86_64
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva foomatic-filters-4.0.1-1.2mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva foomatic-filters-4.0.1-1.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2010.1 x86_64
-
Mandriva foomatic-filters-4.0.3-2.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2010.1
-
Mandriva foomatic-filters-4.0.3-2.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2009.0
-
Mandriva foomatic-filters-4.0.1-1.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Corporate Server 4.0
-
Mandriva foomatic-filters-3.0.2-1.20060827.1.1.20060mlcs4.noarch.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva foomatic-filters-4.0.1-1.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva foomatic-filters-3.0.2-1.20060827.1.1.20060mlcs4.noarch.rpm
http://www.mandriva.com/en/downloads/
References
Foomatic 'foomatic-rip' Command Injection Vulnerability
References:
References:
- Bug 698451 - VUL-0: foomatic-filters and hplip: arbitrary remote code execution (Novell)
- Product Homepage (Foomatic)
- Avaya Aura System Manager (Avaya)