Bug 130949 - CAN-2004-0801 foomatic-rip arbitrary command execution issue
Summary: CAN-2004-0801 foomatic-rip arbitrary command execution issue
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: foomatic
Version: 2
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Tim Waugh
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2004-08-25 23:11 UTC by Josh Bressers
Modified: 2007-11-30 22:10 UTC (History)
2 users (show)

Fixed In Version: 3.0.2-19
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2005-08-20 06:24:33 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Josh Bressers 2004-08-25 23:11:41 UTC
The cupsomatic driver in foomatic has an issue where if a properly
named file is handed to lpr for printing, it can cause arbitrary
command execution.

I'll attach the patch when it becomes available.

This issue should also affect FC1.

Comment 1 Tim Waugh 2004-09-10 12:02:06 UTC
Candidate packages built (FEDORA-2004-302, FEDORA-2004-303).  Awaiting
release date for push.

Comment 2 Josh Bressers 2004-09-15 14:04:16 UTC
Removing embargo

Comment 3 Marius Andreiana 2005-08-20 06:24:33 UTC
FC4 includes the fixes.


Note You need to log in before you can comment on or make changes to this bug.