cups-filters CVE-2014-4336 Incomplete Fix Arbitrary Command Execution Vulnerability
BID:68121
Info
cups-filters CVE-2014-4336 Incomplete Fix Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 68121 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-4336 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2014 12:00AM |
| Updated: | Mar 19 2015 08:35AM |
| Credit: | Sebastian Krahmer |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
cups-filters CVE-2014-4336 Incomplete Fix Arbitrary Command Execution Vulnerability
cups-filters is prone to a remote arbitrary command-execution vulnerability because it fails to sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary commands within the context of the vulnerable application.
Note: This issue exists due to an incomplete fix for CVE-2014-2707 (identified in BID 66624- cups-filters CVE-2014-2707 Arbitrary Command Execution Vulnerability).
cups-filters is prone to a remote arbitrary command-execution vulnerability because it fails to sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary commands within the context of the vulnerable application.
Note: This issue exists due to an incomplete fix for CVE-2014-2707 (identified in BID 66624- cups-filters CVE-2014-2707 Arbitrary Command Execution Vulnerability).
Exploit / POC
cups-filters CVE-2014-4336 Incomplete Fix Arbitrary Command Execution Vulnerability
Attacker can exploit this issue using readily available tools.
Attacker can exploit this issue using readily available tools.
Solution / Fix
cups-filters CVE-2014-4336 Incomplete Fix Arbitrary Command Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
cups-filters CVE-2014-4336 Incomplete Fix Arbitrary Command Execution Vulnerability
References:
References:
- Re: cups-browsed remote exploit (Jamie Strandboge)
- Additional fixing for CVE-2014-2707 (initial fix in 1.0.51) (Linux)
- cups-filters Homepage (linuxfoundation)