Candidate: CVE-2010-5325 PublicDate: 2016-04-15 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5325 https://bugs.linuxfoundation.org/show_bug.cgi?id=515 https://bugzilla.redhat.com/show_bug.cgi?id=1218297 http://bzr.linuxfoundation.org/loggerhead/openprinting/foomatic/foomatic-filters/revision/239 (HEAD) http://bzr.linuxfoundation.org/loggerhead/openprinting/foomatic-4.0/foomatic-filters/revision/225 (4.0.x branch) Description: Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via a long job title. Ubuntu-Description: Notes: sbeattie> code not present in cups-filters/precise, fixed in later versions Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_foomatic-filters: upstream_foomatic-filters: released (4.0.6-1) precise_foomatic-filters: not-affected (4.0.16-0ubuntu0.4) trusty_foomatic-filters: not-affected trusty/esm_foomatic-filters: DNE (trusty was not-affected) vivid/stable-phone-overlay_foomatic-filters: DNE vivid/ubuntu-core_foomatic-filters: DNE wily_foomatic-filters: not-affected devel_foomatic-filters: not-affected Patches_cups-filters: upstream_cups-filters: released (1.0.42) precise_cups-filters: not-affected (code not present) trusty_cups-filters: not-affected trusty/esm_cups-filters: DNE (trusty was not-affected) vivid/stable-phone-overlay_cups-filters: DNE vivid/ubuntu-core_cups-filters: DNE wily_cups-filters: not-affected devel_cups-filters: not-affected