Jump to content

Advisories MDVSA-2010:073-1: cups


paul
 Share

Recommended Posts

Multiple vulnerabilities has been found and corrected in cups:

 

CUPS in does not properly handle (1) HTTP headers and (2) HTML

templates, which allows remote attackers to conduct cross-site

scripting (XSS) attacks and HTTP response splitting attacks via vectors

related to (a) the product's web interface, (B) the configuration of

the print system, and © the titles of printed jobs (CVE-2009-2820).

 

Use-after-free vulnerability in the abstract file-descriptor handling

interface in the cupsdDoSelect function in scheduler/select.c in the

scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers

to cause a denial of service (daemon crash or hang) via a client

disconnection during listing of a large number of print jobs, related

to improperly maintaining a reference count. NOTE: some of these

details are obtained from third party information (CVE-2009-3553).

 

Use-after-free vulnerability in the abstract file-descriptor handling

interface in the cupsdDoSelect function in scheduler/select.c in the

scheduler in cupsd in CUPS 1.3.7, 1.3.9, 1.3.10, and 1.4.1, when kqueue

or epoll is used, allows remote attackers to cause a denial of service

(daemon crash or hang) via a client disconnection during listing

of a large number of print jobs, related to improperly maintaining

a reference count. NOTE: some of these details are obtained from

third party information. NOTE: this vulnerability exists because of

an incomplete fix for CVE-2009-3553 (CVE-2010-0302).

 

The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS

1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable

to determine the file that provides localized message strings, which

allows local users to gain privileges via a file that contains crafted

localization data with format string specifiers (CVE-2010-0393).

 

The updated packages have been patched to correct these issues.

 

Update:

 

Packages for Mandriva Linux 2010.0 was missing with

MDVSA-2010:073. This advisory provides packages for 2010.0 as well.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...