============================================================================ Ubuntu Security Notice USN-2838-1 December 16, 2015 cups-filters vulnerability ============================================================================ A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.10 - Ubuntu 15.04 - Ubuntu 14.04 LTS Summary: cups-filters could be made to run programs as the lp user if it processed a specially crafted print job. Software Description: - cups-filters: OpenPrinting CUPS Filters Details: Adam Chester discovered that the cups-filters foomatic-rip filter incorrectly stripped shell escape characters. A remote attacker could possibly use this issue to execute arbitrary code as the lp user. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: cups-filters 1.0.76-1ubuntu0.2 Ubuntu 15.04: cups-filters 1.0.67-0ubuntu2.6 Ubuntu 14.04 LTS: cups-filters 1.0.52-0ubuntu1.7 In general, a standard system update will make all the necessary changes. References: http://www.ubuntu.com/usn/usn-2838-1 CVE-2015-8560 Package Information: https://launchpad.net/ubuntu/+source/cups-filters/1.0.76-1ubuntu0.2 https://launchpad.net/ubuntu/+source/cups-filters/1.0.67-0ubuntu2.6 https://launchpad.net/ubuntu/+source/cups-filters/1.0.52-0ubuntu1.7