MGASA-2014-0313
Dashboard / Vulnerabilities / MGASA-2014-0313
MGASA-2014-0313
Summary: Updated cups packages fix security vulnerability
Details: In CUPS before 1.7.4, a local user with privileges of group=lp can write symbolic links in the rss directory and use that to gain '@SYSTEM' group privilege with cupsd (CVE-2014-3537). It was discovered that the web interface in CUPS incorrectly validated permissions on rss files and directory index files. A local attacker could possibly use this issue to bypass file permissions and read arbitrary files, possibly leading to a privilege escalation (CVE-2014-5029, CVE-2014-5030, CVE-2014-5031).
References: https://advisories.mageia.org/MGASA-2014-0313.html, https://bugs.mageia.org/show_bug.cgi?id=13783, https://lists.fedoraproject.org/pipermail/package-announce/2014-July/135528.html, https://www.debian.org/security/2014/dsa-2990
Affected packages
Package
Name: cups
Purl: pkg:rpm/mageia/cups?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
