Advisories ยป MGASA-2015-0247

Updated cups package fixes security vulnerabilities

Publication date: 19 Jun 2015
Modification date: 19 Jun 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2015-1158 , CVE-2015-1159

Description

It was discovered that CUPS incorrectly handled reference counting when
handling localized strings. A remote attacker could use this issue to
escalate permissions, upload a replacement CUPS configuration file, and
execute arbitrary code (CVE-2015-1158).

It was discovered that the CUPS templating engine contained a cross-site
scripting issue. A remote attacker could use this issue to bypass default
configuration settings (CVE-2015-1159).

It was discovered that the CUPS server can get stuck in an infinite loop when
a user queues a malformed gzip file. When this happens the CUPS server will
be unable to service any further requests (STR#4602).
                

References

SRPMS

4/core