MGASA-2014-0170
Dashboard / Vulnerabilities / MGASA-2014-0170
MGASA-2014-0170
Summary: Updated cups-filters packages fix security vulnerabilities
Details: Updated cups-filters packages fix security vulnerabilities: Florian Weimer discovered that cups-filters incorrectly handled memory in the urftopdf filter. An attacker could possibly use this issue to execute arbitrary code with the privileges of the lp user (CVE-2013-6473). Florian Weimer discovered that cups-filters incorrectly handled memory in the pdftoopvp filter. An attacker could possibly use this issue to execute arbitrary code with the privileges of the lp user (CVE-2013-6474, CVE-2013-6475). Florian Weimer discovered that cups-filters did not restrict driver directories in the pdftoopvp filter. An attacker could possibly use this issue to execute arbitrary code with the privileges of the lp user (CVE-2013-6476).
References: https://advisories.mageia.org/MGASA-2014-0170.html, http://www.ubuntu.com/usn/usn-2143-1/, https://bugs.mageia.org/show_bug.cgi?id=13002
Affected packages
Package
Name: cups-filters
Purl: pkg:rpm/mageia/cups-filters?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
