First published: Thu Aug 04 2011(Updated: )
It was reported [1] that pysmb.py in system-config-printer does not sanitize a host's netbios name or workgroup/domain name. A specially crafted netbios name on the local network could cause pysmb.py to execute arbitrary commands based on the hostname. This was originally reported in Ubuntu against foomatic-gui, and has been patched [2], however the origin of the script in foomatic-gui is in the system-config-printer package. If a remote SMB server on the local network had a crafted hostname and a user ran pysmb.py, it would be possible for shell commands to be executed with the privileges of the user running pysmb.py. The pysmb.py script in Red Hat Enterprise Linux 6 does not use os.popen(). [1] <a href="https://bugs.launchpad.net/ubuntu/+source/foomatic-gui/+bug/811119">https://bugs.launchpad.net/ubuntu/+source/foomatic-gui/+bug/811119</a> [2] <a href="http://cvs.savannah.gnu.org/viewvc/foomatic-gui/foomatic/pysmb.py?root=foomatic-gui&r1=1.2&r2=1.3&view=patch">http://cvs.savannah.gnu.org/viewvc/foomatic-gui/foomatic/pysmb.py?root=foomatic-gui&r1=1.2&r2=1.3&view=patch</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat system-config-printer | =0.7.82.4 | |
Red Hat system-config-printer | =0.7.65 | |
Red Hat system-config-printer | =0.7.79 | |
Red Hat system-config-printer | =0.7.78 | |
Red Hat system-config-printer | =0.7.74.11 | |
Red Hat system-config-printer | =0.7.32.10 | |
Red Hat system-config-printer | =0.7.82.3 | |
Red Hat system-config-printer | =0.7.82 | |
Red Hat system-config-printer | =0.7.62 | |
Red Hat system-config-printer | =0.7.82.1 | |
Red Hat system-config-printer | =0.7.76 | |
Red Hat system-config-printer | =0.7.80 | |
Red Hat system-config-printer | =0.7.75 | |
Red Hat system-config-printer | =0.7.74.12 | |
Red Hat system-config-printer | =0.7.60 | |
Red Hat system-config-printer | =0.7.73 | |
Red Hat system-config-printer | =0.7.63.3 | |
Red Hat system-config-printer | =0.7.74.4 | |
Red Hat system-config-printer | =0.7.82.5 | |
Red Hat system-config-printer | =0.7.74.2 | |
Red Hat system-config-printer | =0.7.74.1 | |
Red Hat system-config-printer | =0.7.74.7 | |
Red Hat system-config-printer | =0.7.61 | |
Red Hat system-config-printer | =0.7.32.6 | |
Red Hat system-config-printer | =0.7.72 | |
Red Hat system-config-printer | =0.7.64 | |
Red Hat system-config-printer | =0.7.74.5 | |
Red Hat system-config-printer | =0.7.74.6 | |
Red Hat system-config-printer | =0.7.67 | |
Red Hat system-config-printer | =0.7.66 | |
Red Hat system-config-printer | =0.7.32.9 | |
Red Hat system-config-printer | =0.7.74.8 | |
Red Hat system-config-printer | =0.7.81 | |
Red Hat system-config-printer | =0.7.63.4 | |
Red Hat system-config-printer | =0.7.74.10 | |
Red Hat system-config-printer | =0.7.74.3 | |
Red Hat system-config-printer | =0.7.69 | |
Red Hat system-config-printer | =0.7.74.13 | |
Red Hat system-config-printer | =0.7.32.8 | |
Red Hat system-config-printer | =0.7.32.7 | |
Red Hat system-config-printer | =0.7.82.2 | |
Red Hat system-config-printer | =0.7.63 | |
Red Hat system-config-printer | =0.7.68 | |
Red Hat system-config-printer | =0.7.71 | |
Red Hat system-config-printer | =0.7.74.9 | |
Red Hat system-config-printer | =0.7.70 | |
Red Hat system-config-printer | =0.7.63.2 | |
Red Hat system-config-printer | =0.7.63.1 | |
Red Hat system-config-printer | =0.7.74 | |
Red Hat system-config-printer | =0.7.77 | |
Red Hat system-config-printer | =0.6.37 | |
Red Hat system-config-printer | =0.6.4 | |
Red Hat system-config-printer | =0.6.32 | |
Red Hat system-config-printer | =0.6.23 | |
Red Hat system-config-printer | =0.6.38 | |
Red Hat system-config-printer | =0.6.29 | |
Red Hat system-config-printer | =0.6.103 | |
Red Hat system-config-printer | =0.6.19 | |
Red Hat system-config-printer | =0.6.106 | |
Red Hat system-config-printer | =0.6.82 | |
Red Hat system-config-printer | =0.6.27 | |
Red Hat system-config-printer | =0.6.75 | |
Red Hat system-config-printer | =0.6.87 | |
Red Hat system-config-printer | =0.6.102 | |
Red Hat system-config-printer | =0.6.85 | |
Red Hat system-config-printer | =0.6.10 | |
Red Hat system-config-printer | =0.6.68 | |
Red Hat system-config-printer | =0.6.101 | |
Red Hat system-config-printer | =0.6.65 | |
Red Hat system-config-printer | =0.6.47 | |
Red Hat system-config-printer | =0.6.20 | |
Red Hat system-config-printer | =0.6.110 | |
Red Hat system-config-printer | =0.6.13 | |
Red Hat system-config-printer | =0.6.81 | |
Red Hat system-config-printer | =0.6.45 | |
Red Hat system-config-printer | =0.6.36 | |
Red Hat system-config-printer | =0.6.17 | |
Red Hat system-config-printer | =0.6.2 | |
Red Hat system-config-printer | =0.6.104 | |
Red Hat system-config-printer | =0.6.63 | |
Red Hat system-config-printer | =0.6.113 | |
Red Hat system-config-printer | =0.6.51 | |
Red Hat system-config-printer | =0.6.83 | |
Red Hat system-config-printer | =0.6.62 | |
Red Hat system-config-printer | =0.6.25 | |
Red Hat system-config-printer | =0.6.35 | |
Red Hat system-config-printer | =0.6.98 | |
Red Hat system-config-printer | =0.6.21 | |
Red Hat system-config-printer | =0.6.31 | |
Red Hat system-config-printer | =0.6.54 | |
Red Hat system-config-printer | =0.6.49 | |
Red Hat system-config-printer | =0.6.8 | |
Red Hat system-config-printer | =0.6.40 | |
Red Hat system-config-printer | =0.6.9 | |
Red Hat system-config-printer | =0.6.53 | |
Red Hat system-config-printer | =0.6.41 | |
Red Hat system-config-printer | =0.6.116 | |
Red Hat system-config-printer | =0.6.95 | |
Red Hat system-config-printer | =0.6.46 | |
Red Hat system-config-printer | =0.6.73 | |
Red Hat system-config-printer | =0.6.0 | |
Red Hat system-config-printer | =0.6.42 | |
Red Hat system-config-printer | =0.6.70 | |
Red Hat system-config-printer | =0.6.107 | |
Red Hat system-config-printer | =0.6.89 | |
Red Hat system-config-printer | =0.6.93 | |
Red Hat system-config-printer | =0.6.80 | |
Red Hat system-config-printer | =0.6.59 | |
Red Hat system-config-printer | =0.6.24 | |
Red Hat system-config-printer | =0.6.39 | |
Red Hat system-config-printer | =0.6.76 | |
Red Hat system-config-printer | =0.6.84 | |
Red Hat system-config-printer | =0.6.86 | |
Red Hat system-config-printer | =0.6.109 | |
Red Hat system-config-printer | =0.6.57 | |
Red Hat system-config-printer | =0.6.26 | |
Red Hat system-config-printer | =0.6.12 | |
Red Hat system-config-printer | =0.6.15 | |
Red Hat system-config-printer | =0.6.66 | |
Red Hat system-config-printer | =0.6.3 | |
Red Hat system-config-printer | =0.6.111 | |
Red Hat system-config-printer | =0.6.90 | |
Red Hat system-config-printer | =0.6.18 | |
Red Hat system-config-printer | =0.6.100 | |
Red Hat system-config-printer | =0.6.16 | |
Red Hat system-config-printer | =0.6.56 | |
Red Hat system-config-printer | =0.6.72 | |
Red Hat system-config-printer | =0.6.79 | |
Red Hat system-config-printer | =0.6.50 | |
Red Hat system-config-printer | =0.6.105 | |
Red Hat system-config-printer | =0.6.77 | |
Red Hat system-config-printer | =0.6.99 | |
Red Hat system-config-printer | =0.6.34 | |
Red Hat system-config-printer | =0.6.108 | |
Red Hat system-config-printer | =0.6.52 | |
Red Hat system-config-printer | =0.6.92 | |
Red Hat system-config-printer | =0.6.78 | |
Red Hat system-config-printer | =0.6.96 | |
Red Hat system-config-printer | =0.6.58 | |
Red Hat system-config-printer | =0.6.115 | |
Red Hat system-config-printer | =0.6.67 | |
Red Hat system-config-printer | =0.6.60 | |
Red Hat system-config-printer | =0.6.69 | |
Red Hat system-config-printer | =0.6.5 | |
Red Hat system-config-printer | =0.6.48 | |
Red Hat system-config-printer | =0.6.33 | |
Red Hat system-config-printer | =0.6.94 | |
Red Hat system-config-printer | =0.6.30 | |
Red Hat system-config-printer | =0.6.74 | |
Red Hat system-config-printer | =0.6.114 | |
Red Hat system-config-printer | =0.6.112 | |
Red Hat system-config-printer | =0.6.7 | |
Red Hat system-config-printer | =0.6.28 | |
Red Hat system-config-printer | =0.6.44 | |
Red Hat system-config-printer | =0.6.14 | |
Red Hat system-config-printer | =0.6.6 | |
Red Hat system-config-printer | =0.6.22 | |
Red Hat system-config-printer | =0.6.97 | |
Red Hat system-config-printer | =0.6.1 | |
Red Hat system-config-printer | =0.6.71 | |
Red Hat system-config-printer | =0.6.61 | |
Red Hat system-config-printer | =0.6.64 | |
Red Hat system-config-printer | =0.6.55 | |
Red Hat system-config-printer | =0.6.91 | |
Red Hat system-config-printer | =0.6.88 | |
Red Hat system-config-printer | =0.6.11 | |
Red Hat system-config-printer | =0.6.43 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-2899 is classified as high due to its potential to allow arbitrary code execution through crafted netbios names.
To fix CVE-2011-2899, upgrade to the patched version of system-config-printer as provided by your distribution.
CVE-2011-2899 affects multiple versions of the system-config-printer software, including versions 0.6.0 through 0.7.82.
The impact of CVE-2011-2899 includes the ability for an attacker to execute arbitrary commands on a vulnerable system remotely.
While there are no current reports of active exploitation for CVE-2011-2899, it is recommended to remediate the vulnerability promptly.