RHSA-2016:0491: Moderate: foomatic security update
Foomatic is a comprehensive, spooler-independent database of printers,printer drivers, and driver descriptions. The package also includesspooler-independent command line interfaces to manipulate queues and toprint files and manipulate print jobs.It was discovered that the unhtmlify() function of foomatic-rip did notcorrectly calculate buffer sizes, possibly leading to a heap-based memorycorruption. A malicious attacker could exploit this flaw to causefoomatic-rip to crash or, possibly, execute arbitrary code.(CVE-2010-5325)It was discovered that foomatic-rip failed to remove all shell specialcharacters from inputs used to construct command lines for externalprograms run by the filter. An attacker could possibly use this flaw toexecute arbitrary commands. (CVE-2015-8327, CVE-2015-8560)All foomatic users should upgrade to this updated package, which containsbackported patches to correct these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2016:0491?
The severity of RHSA-2016:0491 is classified as important.
How do I fix RHSA-2016:0491?
To fix RHSA-2016:0491, update the foomatic package to version 4.0.4-5.el6_7.
What software is affected by RHSA-2016:0491?
RHSA-2016:0491 affects the foomatic package version 4.0.4-5.el6_7 and its debuginfo counterpart.
What is the main issue described in RHSA-2016:0491?
RHSA-2016:0491 addresses a vulnerability in the foomatic printer driver package that could allow unauthorized access.
Is RHSA-2016:0491 applicable to all systems?
RHSA-2016:0491 is specifically applicable to systems running Red Hat Enterprise Linux version 6 with the foomatic package installed.