[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2014:092 -- Mandriva cups

ID: oval:org.secpod.oval:def:1300300Date: (C)2014-06-11   (M)2022-10-10
Class: PATCHFamily: unix




Multiple vulnerabilities has been discovered and corrected in cups: lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf . Cross-site scripting vulnerability in scheduler/client.c in Common Unix Printing System before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function . The updated packages have been patched to correct these issues.

Platform:
Mandriva Enterprise Server 5.2
Product:
cups
Reference:
MDVSA-2014:092
CVE-2013-6891
CVE-2014-2856
CVE    2
CVE-2014-2856
CVE-2013-6891
CPE    2
cpe:/a:cups:cups
cpe:/o:mandriva:enterprise_server:5.2

© SecPod Technologies