← Back

Cups Filters

cups-filters

Vendor: Linuxfoundation • 14 CVEs

CVEs (14)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectLinuxfoundation
3Cups Filters
Debian LinuxFedora
Jun 17, 2026
May 17, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible netw...Show more
cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote code execution. `beh.c` contains the line `retval = system(cmdline) >> 8;` which calls the `system` command with the operand `cmdline`. `cmdline` contains multiple user controlled, unsanitized values. As a result an attacker with network access to the hosted print server can exploit this vulnerability to inject system commands which are executed in the context of the running server. This issue has been addressed in commit `8f2740357` and is expected to be bundled in the next release. Users are advised to upgrade when possible and to restrict access to network printers in the meantime.Show less
3Canonical
DebianLinuxfoundation
4Cups Filters
Debian LinuxFoomatic Filters+1 more
May 6, 2026
Apr 14, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) charact...Show more
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.Show less
4Canonical
DebianLinuxfoundation+1 more
9Cups Filters
Debian LinuxEnterprise Linux Desktop+6 more
May 6, 2026
Dec 17, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters...Show more
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.Show less
3Canonical
DebianLinuxfoundation
3Cups Filters
Debian LinuxUbuntu Linux
May 6, 2026
Jul 14, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted line size in a print job, wh...Show more
Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted line size in a print job, which triggers a heap-based buffer overflow.Show less
3Canonical
DebianLinuxfoundation
3Cups Filters
Debian LinuxUbuntu Linux
May 6, 2026
Jul 14, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via...Show more
Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a small line size in a print job.Show less
2Canonical
Linuxfoundation
2Cups Filters
Ubuntu Linux
May 6, 2026
Mar 24, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vu...Show more
The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.Show less
1Linuxfoundation
1Cups Filters
May 6, 2026
Jun 22, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
cups-browsed in cups-filters before 1.0.53 allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a malformed cups-browsed.conf BrowseAllow directive that is interpret...Show more
cups-browsed in cups-filters before 1.0.53 allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a malformed cups-browsed.conf BrowseAllow directive that is interpreted as granting browse access to all IP addresses.Show less
1Linuxfoundation
1Cups Filters
May 6, 2026
Jun 22, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet da...Show more
The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet data.Show less
1Linuxfoundation
1Cups Filters
May 6, 2026
Jun 22, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vuln...Show more
The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.Show less
1Linuxfoundation
1Cups Filters
May 6, 2026
Apr 17, 2014
N/A· v4
N/A· v3
8.3 HIGH· v2
cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the (1) model or (2) PDL, related to "System V interface scripts generated for queues...Show more
cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the (1) model or (2) PDL, related to "System V interface scripts generated for queues."Show less
4Canonical
DebianFedoraproject+1 more
4Cups Filters
Debian LinuxFedora+1 more
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
4.4 MEDIUM· v2
The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF...Show more
The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF file.Show less
4Canonical
DebianFedoraproject+1 more
4Cups Filters
Debian LinuxFedora+1 more
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, whic...Show more
Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.Show less
4Canonical
DebianFedoraproject+1 more
4Cups Filters
Debian LinuxFedora+1 more
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.
2Canonical
Linuxfoundation
2Cups Filters
Ubuntu Linux
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file.