MGASA-2015-0247
Dashboard / Vulnerabilities / MGASA-2015-0247
Summary: Updated cups package fixes security vulnerabilities
Details: It was discovered that CUPS incorrectly handled reference counting when handling localized strings. A remote attacker could use this issue to escalate permissions, upload a replacement CUPS configuration file, and execute arbitrary code (CVE-2015-1158). It was discovered that the CUPS templating engine contained a cross-site scripting issue. A remote attacker could use this issue to bypass default configuration settings (CVE-2015-1159). It was discovered that the CUPS server can get stuck in an infinite loop when a user queues a malformed gzip file. When this happens the CUPS server will be unable to service any further requests (STR#4602).
References: https://advisories.mageia.org/MGASA-2015-0247.html, https://bugs.mageia.org/show_bug.cgi?id=16098, http://www.cups.org/str.php?L4609, http://www.cups.org/str.php?L4602, http://www.ubuntu.com/usn/usn-2629-1/
Affected packages
Package
Name: cups
Purl: pkg:rpm/mageia/cups?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
