Rapid7 Vulnerability & Exploit Database

RHSA-2014:1388: cups security and bug fix update

Back to Search

RHSA-2014:1388: cups security and bug fix update

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
07/29/2014
Created
07/25/2018
Added
10/14/2014
Modified
07/04/2017

Description

CUPS provides a portable printing layer for Linux, UNIX, and similaroperating systems.A cross-site scripting (XSS) flaw was found in the CUPS web interface.An attacker could use this flaw to perform a cross-site scripting attackagainst users of the CUPS web interface. (CVE-2014-2856)It was discovered that CUPS allowed certain users to create symbolic linksin certain directories under /var/cache/cups/. A local user with the 'lp'group privileges could use this flaw to read the contents of arbitraryfiles on the system or, potentially, escalate their privileges on thesystem. (CVE-2014-3537, CVE-2014-5029, CVE-2014-5030, CVE-2014-5031)The CVE-2014-3537 issue was discovered by Francisco Alonso of Red HatProduct Security.These updated cups packages also include several bug fixes. Space precludesdocumenting all of these changes in this advisory. Users are directed tothe Red Hat Enterprise Linux 6.6 Technical Notes, linked to in theReferences section, for information on the most significant of thesechanges.All cups users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. After installing thisupdate, the cupsd daemon will be restarted automatically.

Solution(s)

  • redhat-upgrade-cups
  • redhat-upgrade-cups-debuginfo
  • redhat-upgrade-cups-devel
  • redhat-upgrade-cups-libs
  • redhat-upgrade-cups-lpd
  • redhat-upgrade-cups-php

References

  • redhat-upgrade-cups
  • redhat-upgrade-cups-debuginfo
  • redhat-upgrade-cups-devel
  • redhat-upgrade-cups-libs
  • redhat-upgrade-cups-lpd
  • redhat-upgrade-cups-php

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;