This script is Copyright (C) 2004-2015 Tenable Network Security, Inc.
The remote Gentoo host is missing one or more security-related
The remote host is affected by the vulnerability described in GLSA-200409-24
(Foomatic: Arbitrary command execution in foomatic-rip filter)
There is a vulnerability in the foomatic-filters package. This
vulnerability is due to insufficient checking of command-line parameters
and environment variables in the foomatic-rip filter.
This vulnerability may allow both local and remote attackers to execute
arbitrary commands on the print server with the permissions of the spooler
(oftentimes the 'lp' user).
There is no known workaround at this time.
See also :
All foomatic users should upgrade to the latest version:
# emerge sync
# emerge -pv '>=net-print/foomatic-3.0.2'
# emerge '>=net-print/foomatic-3.0.2'
PLEASE NOTE: You should update foomatic, instead of foomatic-filters. This
will help to ensure that all other foomatic components remain functional.
Risk factor :
High / CVSS Base Score : 7.5
Family: Gentoo Local Security Checks
Nessus Plugin ID: 14779 (gentoo_GLSA-200409-24.nasl)
CVE ID: CVE-2004-0801