CVE-2015-2265: Command Injection
The removebadchars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2265?
CVE-2015-2265 has a high severity rating due to the potential for remote command execution.
How do I fix CVE-2015-2265?
To fix CVE-2015-2265, upgrade to cups-filters version 1.0.66 or later.
Which software is affected by CVE-2015-2265?
CVE-2015-2265 affects cups-filters versions prior to 1.0.66 and certain Ubuntu Linux releases including 14.04 and 14.10.
What type of attack does CVE-2015-2265 enable?
CVE-2015-2265 enables remote attackers to execute arbitrary commands via crafted IPP printer data.
Is CVE-2015-2265 a new vulnerability?
CVE-2015-2265 is related to CVE-2014-2707 and represents an incomplete fix for that earlier vulnerability.