Link Following Affecting foomatic-filters package, versions <4.0.12-1


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
0.04% (5th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN12-FOOMATICFILTERS-1546271
  • published27 Jun 2018
  • disclosed19 Nov 2019

Introduced: 27 Jun 2018

CVE-2011-2924  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

Upgrade Debian:12 foomatic-filters to version 4.0.12-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream foomatic-filters package and not the foomatic-filters package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter.

CVSS Scores

version 3.1