CVE-2014-4336
Mandriva Linux Security Advisory 2015-100
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.
La función generate_local_queue en utils/cups-browsed.c en cups-browsed en cups-filters anterior a 1.0.53 permite a impresoras IPP remotas ejecutar comandos arbitrarios a través de metacaracteres de shell en el nombre del anfitrión. NOTA: esta vulnerabilidad existe debido a una solución incompleta para CVE-2014-2707.
Florian Weimer discovered that cups-filters incorrectly handled memory in the urftopdf filter. An attacker could possibly use this issue to execute arbitrary code with the privileges of the lp user. Florian Weimer discovered that cups-filters incorrectly handled memory in the pdftoopvp filter. Various other issues where also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-06-19 CVE Reserved
- 2014-06-22 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://openwall.com/lists/oss-security/2014/06/19/12 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7194 | 2018-01-03 | |
http://openwall.com/lists/oss-security/2014/04/25/7 | 2018-01-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linuxfoundation Search vendor "Linuxfoundation" | Cups-filters Search vendor "Linuxfoundation" for product "Cups-filters" | <= 1.0.52 Search vendor "Linuxfoundation" for product "Cups-filters" and version " <= 1.0.52" | - |
Affected
|