CVE-2011-2964: Code Injection
Published Jul 29, 2011
·Updated
foomaticrip.c in foomatic-rip in foomatic-filters in Foomatic 4.0.6 allows remote attackers to execute arbitrary code via a crafted FoomaticRIPCommandLine field in a .ppd file, a different vulnerability than CVE-2011-2697.
Affected Software
1 affected component
linuxfoundation Foomatic=4.0.6
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jul 29, 2011
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2964?
CVE-2011-2964 is considered a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2011-2964?
To fix CVE-2011-2964, upgrade to a patched version of Foomatic that addresses this vulnerability.
3
What kind of attack exploits CVE-2011-2964?
CVE-2011-2964 can be exploited by an attacker sending a crafted .ppd file containing a malicious FoomaticRIPCommandLine field.
4
Which versions of Foomatic are affected by CVE-2011-2964?
CVE-2011-2964 specifically affects Foomatic version 4.0.6.
5
Is CVE-2011-2964 related to any other vulnerabilities?
Yes, CVE-2011-2964 is a different vulnerability than CVE-2011-2697, although they both affect the same software.