NASLDB: RHSA-2005-013: cups
General
ID: 16146
Name: RHSA-2005-013: cups
Summary: Check for the version of the cups packages
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS Temporal Vector: –
Port: 0
Family: Red Hat Local Security Checks
Type: Local
Description
Updated CUPS packages that fix several security issues are now available.
The Common UNIX Printing System provides a portable printing layer for
UNIX operating systems.
A buffer overflow was found in the CUPS pdftops filter, which uses code
from the Xpdf package. An attacker who has the ability to send a malicious
PDF file to a printer could possibly execute arbitrary code as the "lp"
user. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1125 to this issue.
A buffer overflow was found in the ParseCommand function in the hpgltops
program. An attacker who has the ability to send a malicious HPGL file to a
printer could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1267 to this issue.
Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit these buffer overflow
vulnerabilities on x86 architectures.
The lppasswd utility ignores write errors when modifying the CUPS passwd
file. A local user who is able to fill the associated file system could
corrupt the CUPS password file or prevent future uses of lppasswd. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the names CAN-2004-1268 and CAN-2004-1269 to these issues.
The lppasswd utility does not verify that the passwd.new file is different
from STDERR, which could allow local users to control output to passwd.new
via certain user input that triggers an error message. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1270 to this issue.
In addition to these security issues, two other problems not relating
to security have been fixed:
Resuming a job with "lp -H resume", which had previously been held with "lp
-H hold" could cause the scheduler to stop. This has been fixed in later
versions of CUPS, and has been backported in these updated packages.
The cancel-cups(1) man page is a symbolic link to another man page. The
target of this link has been corrected.
All users of cups should upgrade to these updated packages, which resolve
these issues.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2004-1125
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: –
Plugin Release: 2005/01/13
Plugin
Version: 1.11
Filename: redhat-RHSA-2005-013.nasl
Filesize: 4230 bytes
MD5 Hash: bc2ad670f845f2b55bcaaa463ec61049
Identification: Host/RedHat/rpm-list
Require Keys: Host/RedHat/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2005-2011 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













