Bug 1291227 - (CVE-2015-8560) CVE-2015-8560 cups-filters: foomatic-rip did not consider semicolon as illegal shell escape character
CVE-2015-8560 cups-filters: foomatic-rip did not consider semicolon as illega...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20151212,repor...
: Security
Depends On: 1291228 1291229 1301076 1301077
Blocks: 1287524 1291230
  Show dependency treegraph
 
Reported: 2015-12-14 06:17 EST by Adam Mariš
Modified: 2016-04-15 05:39 EDT (History)
4 users (show)

See Also:
Fixed In Version: cups-filters 1.4.0
Doc Type: Bug Fix
Doc Text:
It was discovered that foomatic-rip failed to remove all shell special characters from inputs used to construct command lines for external programs run by the filter. An attacker could possibly use this flaw to execute arbitrary commands.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Adam Mariš 2015-12-14 06:17:41 EST
Following security fix was released in v1.4.0:

- foomatic-rip: SECURITY FIX: Also consider the semicolon (';') as an illegal shell escape character. Thanks to Adam Chester (adam dot chester at pentest dot co dot uk) for the hint.

Upstream patch:

http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7419

CVE request:

http://seclists.org/oss-sec/2015/q4/479
Comment 1 Adam Mariš 2015-12-14 06:18:16 EST
Created foomatic tracking bugs for this issue:

Affects: fedora-all [bug 1291229]
Comment 2 Adam Mariš 2015-12-14 06:18:22 EST
Created cups-filters tracking bugs for this issue:

Affects: fedora-all [bug 1291228]
Comment 3 Tomas Hoger 2015-12-14 06:43:54 EST
In terms of affected products and components (with respect to foomatic-filters packaged in cups-fitlers or foomatic packages), this issue is similar to CVE-2015-8327, see bug 1287523 comment 2.
Comment 4 Fedora Update System 2015-12-19 13:25:47 EST
cups-filters-1.4.0-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
Comment 5 Fedora Update System 2015-12-30 12:50:08 EST
cups-filters-1.4.0-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
Comment 7 errata-xmlrpc 2016-03-22 17:04:06 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2016:0491 https://rhn.redhat.com/errata/RHSA-2016-0491.html

Note You need to log in before you can comment on or make changes to this bug.