[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2014:1795 -- centos 7 cups-filters

ID: oval:org.secpod.oval:def:203477Date: (C)2014-11-06   (M)2022-10-10
Class: PATCHFamily: unix




The cups-filters package contains backends, filters, and other software that was once part of the core CUPS distribution but is now maintained independently. An out-of-bounds read flaw was found in the way the process_browse_data function of cups-browsed handled certain browse packets. A remote attacker could send a specially crafted browse packet that, when processed by cups-browsed, would crash the cups-browsed daemon. A flaw was found in the way the cups-browsed daemon interpreted the "BrowseAllow" directive in the cups-browsed.conf file. An attacker able to add a malformed "BrowseAllow" directive to the cups-browsed.conf file could use this flaw to bypass intended access restrictions. All cups-filters users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing this update, the cups-browsed daemon will be restarted automatically.

Platform:
CentOS 7
Product:
cups-filters
Reference:
CESA-2014:1795
CVE-2014-4337
CVE-2014-4338
CVE    2
CVE-2014-4338
CVE-2014-4337
CPE    55
cpe:/a:linuxfoundation:cups-filters:1.0.48
cpe:/a:linuxfoundation:cups-filters:1.0.47
cpe:/a:linuxfoundation:cups-filters:1.0.49
cpe:/a:linuxfoundation:cups-filters:1.0.44
...

© SecPod Technologies