ALT-PU-2014-1513-1
Closed vulnerabilities
Published: 2014-01-26
Modified: 2025-04-11
Modified: 2025-04-11
CVE-2013-6891
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
Severity: LOW (1.2)
Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N
References:
- http://advisories.mageia.org/MGASA-2014-0021.html
- http://secunia.com/advisories/56531
- http://www.cups.org/blog.php?L704
- http://www.cups.org/str.php?L4319
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:015
- http://www.ubuntu.com/usn/USN-2082-1
- http://advisories.mageia.org/MGASA-2014-0021.html
- http://secunia.com/advisories/56531
- http://www.cups.org/blog.php?L704
- http://www.cups.org/str.php?L4319
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:015
- http://www.ubuntu.com/usn/USN-2082-1
Published: 2014-04-18
Modified: 2025-04-12
Modified: 2025-04-12
CVE-2014-2856
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
Severity: MEDIUM (4.3)
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
References:
- http://advisories.mageia.org/MGASA-2014-0193.html
- http://rhn.redhat.com/errata/RHSA-2014-1388.html
- http://secunia.com/advisories/57880
- http://www.cups.org/documentation.php/relnotes.html
- http://www.cups.org/str.php?L4356
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:108
- http://www.openwall.com/lists/oss-security/2014/04/14/2
- http://www.openwall.com/lists/oss-security/2014/04/15/3
- http://www.securityfocus.com/bid/66788
- http://www.ubuntu.com/usn/USN-2172-1
- http://advisories.mageia.org/MGASA-2014-0193.html
- http://rhn.redhat.com/errata/RHSA-2014-1388.html
- http://secunia.com/advisories/57880
- http://www.cups.org/documentation.php/relnotes.html
- http://www.cups.org/str.php?L4356
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:108
- http://www.openwall.com/lists/oss-security/2014/04/14/2
- http://www.openwall.com/lists/oss-security/2014/04/15/3
- http://www.securityfocus.com/bid/66788
- http://www.ubuntu.com/usn/USN-2172-1
Closed bugs
удалите поддержку /lib/udev/devices
Добавить provides: cups-libs
Вышла немного починенная версия 1.7.1 просьба собрать