| Package: | foomatic-filters |
| Date: | 2011-09-03 |
| Posted by: | Miklos Vajna |
| Vulnerable version: | 4.0.1-5 |
| Unaffected version: | 4.0.1-6mores1 |
| Bug tracker entry: | http://bugs.frugalware.org/task/4556 |
| CVEs: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2924 |
| Description: | It was found that foomatic-rip filter used insecurely created temporary file for storage of PostScript data by rendering the data, intended to be sent to the PostScript filter, when the debug mode was enabled. A local attacker could use this flaw to conduct symlink attacks (overwrite arbitrary file accessible with the privileges of the user running the foomatic-rip universal print filter). |













