8.3
CVSSv2

CVE-2014-2707

Published: 17/04/2014 Updated: 26/06/2014
CVSS v2 Base Score: 8.3 | Impact Score: 10 | Exploitability Score: 6.5
VMScore: 739
Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

cups-browsed in cups-filters 1.0.41 prior to 1.0.51 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the (1) model or (2) PDL, related to "System V interface scripts generated for queues."

Vulnerable Product Search on Vulmon Subscribe to Product

linuxfoundation cups-filters 1.0.49

linuxfoundation cups-filters 1.0.50

linuxfoundation cups-filters 1.0.47

linuxfoundation cups-filters 1.0.48

linuxfoundation cups-filters 1.0.43

linuxfoundation cups-filters 1.0.44

linuxfoundation cups-filters 1.0.41

linuxfoundation cups-filters 1.0.42

linuxfoundation cups-filters 1.0.45

linuxfoundation cups-filters 1.0.46

Vendor Advisories

Debian Bug report logs - #743470 cups-filters: CVE-2014-2707: remote command injection in cups-browsed Package: src:cups-filters; Maintainer for src:cups-filters is Debian Printing Team <debian-printing@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 3 Apr 2014 04:45:07 UTC Severi ...
Several security issues were fixed in cups-filters ...