MGASA-2015-0132
Dashboard / Vulnerabilities / MGASA-2015-0132
Summary: Updated cups-filters packages fix CVE-2015-2265
Details: Updated cups-filters package fixes security vulnerability: cups-browsed in cups-filters before 1.0.66 contained a bug in the remove_bad_chars() function, where it failed to reliably filter out illegal characters if there were two or more subsequent illegal characters, allowing execution of arbitrary commands with the rights of the "lp" user, using forged print service announcements on DNS-SD servers (CVE-2015-2265).
References: https://advisories.mageia.org/MGASA-2015-0132.html, https://bugs.mageia.org/show_bug.cgi?id=15424, https://bugs.linuxfoundation.org/show_bug.cgi?id=1265, http://www.ubuntu.com/usn/usn-2532-1/
Affected packages
Package
Name: cups-filters
Purl: pkg:rpm/mageia/cups-filters?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
