CVE-2011-2899
pysmb.py in system-config-printer 0.6.x and 0.7.x, as used in foomatic-gui and possibly other products, allows remote SMB servers to execute arbitrary commands via shell metacharacters in the (1) NetBIOS or (2) workgroup name, which are not properly…
Does this matter?
Lower severity and a low EPSS score (1.97%). Track it; it rarely justifies an emergency change on its own.
Description
pysmb.py in system-config-printer 0.6.x and 0.7.x, as used in foomatic-gui and possibly other products, allows remote SMB servers to execute arbitrary commands via shell metacharacters in the (1) NetBIOS or (2) workgroup name, which are not properly handled when searching for network printers.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 1.97% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- redhat/system-config-printer
- Source
- secalert@redhat.com
References
- http://cvs.savannah.gnu.org/viewvc/foomatic-gui/foomatic/pysmb.py?root=foomatic-gui&r1=1.2&r2=1.3&view=patchPatch
- http://secunia.com/advisories/45744Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1196.htmlVendor Advisory
- http://www.securitytracker.com/id?1025967
- https://bugs.launchpad.net/ubuntu/+source/foomatic-gui/+bug/811119Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=728348Patch
- http://cvs.savannah.gnu.org/viewvc/foomatic-gui/foomatic/pysmb.py?root=foomatic-gui&r1=1.2&r2=1.3&view=patchPatch
- http://secunia.com/advisories/45744Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1196.htmlVendor Advisory
- http://www.securitytracker.com/id?1025967
- https://bugs.launchpad.net/ubuntu/+source/foomatic-gui/+bug/811119Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=728348Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.