USN-2629-1
Dashboard / Vulnerabilities / USN-2629-1
USN-2629-1
Summary: cups vulnerabilities
Details: It was discovered that CUPS incorrectly handled reference counting when handling localized strings. A remote attacker could use this issue to escalate permissions, upload a replacement CUPS configuration file, and execute arbitrary code. (CVE-2015-1158) It was discovered that the CUPS templating engine contained a cross-site scripting issue. A remote attacker could use this issue to bypass default configuration settings. (CVE-2015-1159)
References: https://ubuntu.com/security/notices/USN-2629-1, https://ubuntu.com/security/CVE-2015-1158, https://ubuntu.com/security/CVE-2015-1159
Affected packages
Package
Name: cups
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
