CVE-2015-8560

HIGH

cups-filters <1.4.0 - Command Injection

Title source: llm
STIX 2.1

Description

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.

References (10)

Core 10
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3419
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/12/14/13
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2838-1
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3429
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2838-2
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/12/13/2
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-0491.html

Scores

CVSS v3 7.3
EPSS 0.0926
EPSS Percentile 92.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

Status published
Products (50)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 15.04
canonical/ubuntu_linux 15.10
debian/debian_linux 8.0
linuxfoundation/cups-filters 1.0.42
linuxfoundation/cups-filters 1.0.43
linuxfoundation/cups-filters 1.0.44
linuxfoundation/cups-filters 1.0.45
linuxfoundation/cups-filters 1.0.46
... and 40 more
Published Apr 14, 2016
Tracked Since Feb 18, 2026