CVE-2014-4336: Command Injection
Published Jun 22, 2014
·Updated
The generatelocalqueue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.
Affected Software
1 affected component
linuxfoundation cups-filters<=1.0.52
Remediation
Patch Available
Event History
Jun 22, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4336?
CVE-2014-4336 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2014-4336?
To fix CVE-2014-4336, you should update cups-filters to version 1.0.53 or later.
3
What kind of attack does CVE-2014-4336 allow?
CVE-2014-4336 allows remote attackers to execute arbitrary commands on the system via crafted host names.
4
Which versions of cups-filters are affected by CVE-2014-4336?
CVE-2014-4336 affects cups-filters versions prior to 1.0.53.
5
Is CVE-2014-4336 related to any previous vulnerabilities?
Yes, CVE-2014-4336 is related to CVE-2014-2707 as it is based on an incomplete fix.