Jump to content

Advisories MDVSA-2010:233: cups


paul
 Share

Recommended Posts

Multiple vulnerabilities were discovered and corrected in cups:

 

Cross-site request forgery (CSRF) vulnerability in the web interface

in CUPS, allows remote attackers to hijack the authentication of

administrators for requests that change settings (CVE-2010-0540).

 

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate

memory for attribute values with invalid string data types, which

allows remote attackers to cause a denial of service (use-after-free

and application crash) or possibly execute arbitrary code via a

crafted IPP request (CVE-2010-2941).

 

The updated packages have been patched to correct these issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...