CVE-2011-2924

NameCVE-2011-2924
Descriptionfoomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
foomatic-filters (PTS)jessie, jessie (lts)4.0.17-5+deb8u1fixed
stretch4.0.17-9fixed
buster4.0.17-11fixed
bullseye4.0.17-12fixed
sid, trixie, bookworm4.0.17-16fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
foomatic-filterssourcesqueeze4.0.5-6+squeeze2
foomatic-filterssource(unstable)4.0.12-1low

Search for package or bug name: Reporting problems