Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 386279 (CVE-2011-2899)

Summary: <net-print/foomatic-gui-0.7.9.5: remote code execution (CVE-2011-2899)
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: jlec, printing
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: ~1 [noglsa]
Package list:
Runtime testing required: ---

Description GLSAMaker/CVETool Bot gentoo-dev 2011-10-08 13:13:32 UTC
CVE-2011-2899 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2899):
  pysmb.py in system-config-printer 0.6.x and 0.7.x, as used in foomatic-gui
  and possibly other products, allows remote SMB servers to execute arbitrary
  commands via shell metacharacters in the (1) NetBIOS or (2) workgroup name,
  which are not properly handled when searching for network printers.
Comment 1 Justin Lecher (RETIRED) gentoo-dev 2012-01-17 14:08:38 UTC
Just commited the version Bump to 0.7.9.5. This contains the patch [1] to fix the issue mentioned [2].

1
http://cvs.savannah.gnu.org/viewvc/foomatic-gui/foomatic/pysmb.py?root=foomatic-gui&r1=1.2&r2=1.3&view=patch

2
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-2899
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2012-01-18 07:38:14 UTC
Thanks, Justin. Closing noglsa since I don't believe this package currently has stable versions. Please correct me if I am wrong.
Comment 3 Justin Lecher (RETIRED) gentoo-dev 2012-01-18 07:39:39 UTC
You are right. All vulnerable versions have been removed.