7.5
CVSSv2

CVE-2015-2265

Published: 24/03/2015 Updated: 28/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The remove_bad_chars function in utils/cups-browsed.c in cups-filters prior to 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 14.04

canonical ubuntu linux 14.10

linuxfoundation cups-filters

Vendor Advisories

Debian Bug report logs - #780267 cups-filters: CVE-2015-2265 Package: cups-filters; Maintainer for cups-filters is Debian Printing Team <debian-printing@listsdebianorg>; Source for cups-filters is src:cups-filters (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Wed, 11 Mar 2015 12:00:02 ...
cups-filters could be made to run programs if it received specially crafted network traffic ...