CVE-2011-2697
foomatic-filters - shell command injection
EPSS 5.4%
Description
foomatic-rip-hplip in HP Linux Imaging and Printing (HPLIP) 3.11.5 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPCommandLine field in a .ppd file.
How to fix CVE-2011-2697
To remediate CVE-2011-2697, upgrade the affected package to a fixed version below.
- Debian/foomatic-filters—upgrade to 4.0 or later
- Debian/foomatic-filters—upgrade to 4.0.5-6+squeeze1 or later
- Debian/hplip—upgrade to 3.10.6-2 or later
Is CVE-2011-2697 being exploited?
Moderate — EPSS is 5.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 4.0
- from 0, < 4.0.5-6+squeeze1
- from 0, < 3.10.6-2