CVE-2011-2923

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
19/11/2019
Last modified:
21/11/2024

Description

foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:linuxfoundation:foomatic-filters:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*