CVE-2015-8560: High severity ubuntu vulnerability
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8560?
CVE-2015-8560 is classified as a medium severity vulnerability that can allow remote attackers to execute arbitrary commands.
How do I fix CVE-2015-8560?
To fix CVE-2015-8560, update your cups-filters or foomatic-filters package to a version that is 1.4.0 or later for cups-filters and 4.0.17 or later for foomatic-filters.
What systems are affected by CVE-2015-8560?
CVE-2015-8560 affects certain versions of cups-filters and foomatic-filters across various Debian and Ubuntu Linux distributions.
Can CVE-2015-8560 be exploited remotely?
Yes, CVE-2015-8560 can be exploited remotely through specially crafted print jobs containing a semicolon character.
Is there a workaround for CVE-2015-8560 while updates are pending?
A possible workaround is to restrict access to the print service until the vulnerable software is updated.