Unrated severityNVD Advisory· Published Mar 24, 2015· Updated May 6, 2026
CVE-2015-2265
CVE-2015-2265
Description
The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.
Affected products
3cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.ubuntu.com/usn/USN-2532-1nvdPatch
- bugs.linuxfoundation.org/show_bug.cginvdExploit
- bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7333nvdVendor Advisory
- advisories.mageia.org/MGASA-2015-0132.htmlnvd
- lists.opensuse.org/opensuse-updates/2015-07/msg00033.htmlnvd
- www.mandriva.com/security/advisoriesnvd
News mentions
0No linked articles in our index yet.