MDVSA-2014:092 -- Mandriva cupsID: oval:org.secpod.oval:def:1300300 | Date: (C)2014-06-11 (M)2022-10-10 |
Class: PATCH | Family: unix |
Multiple vulnerabilities has been discovered and corrected in cups: lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf . Cross-site scripting vulnerability in scheduler/client.c in Common Unix Printing System before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function . The updated packages have been patched to correct these issues.
Platform: |
Mandriva Enterprise Server 5.2 |