CVE-2015-8560 describes an incomplete blacklist vulnerability in foomatic-rip, affecting cups-filters versions prior to 1.4.0 and Foomatic 4.0.x. This flaw allows remote attackers to execute arbitrary commands by injecting a semicolon into print jobs, impacting Canonical, Debian, and Linux Foundation products. The vulnerability carries a CVSSv3 score of 7.3 (High), indicating a network-based attack with low complexity and no user interaction required, potentially leading to low confidentiality, integrity, and availability impacts. Its EPSS score of 0.10031 suggests a relatively low probability of exploitation. Currently, there is no known active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The CVE has received minimal community discussion and media coverage, suggesting it is not a widely recognized or actively targeted threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
15.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:* | ||
15.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.