LWN.net Logo

cups: multiple vulnerabilities

Package(s):cups CVE #(s):CVE-2010-0540 CVE-2010-0542 CVE-2010-1748
Created:June 18, 2010 Updated:March 2, 2011
Description: From the Red Hat advisory:

A missing memory allocation failure check flaw, leading to a NULL pointer dereference, was found in the CUPS "texttops" filter. An attacker could create a malicious text file that would cause "texttops" to crash or, potentially, execute arbitrary code as the "lp" user if the file was printed. (CVE-2010-0542)

A Cross-Site Request Forgery (CSRF) issue was found in the CUPS web interface. If a remote attacker could trick a user, who is logged into the CUPS web interface as an administrator, into visiting a specially-crafted website, the attacker could reconfigure and disable CUPS, and gain access to print jobs and system files. (CVE-2010-0540)

Note: As a result of the fix for CVE-2010-0540, cookies must now be enabled in your web browser to use the CUPS web interface.

An uninitialized memory read issue was found in the CUPS web interface. If an attacker had access to the CUPS web interface, they could use a specially-crafted URL to leverage this flaw to read a limited amount of memory from the cupsd process, possibly obtaining sensitive information. (CVE-2010-1748)

Alerts:
Debian DSA-2176-1 2011-03-02
SUSE SUSE-SR:2010:023 2010-12-08
openSUSE openSUSE-SU-2010:1018-1 2010-12-06
Mandriva MDVSA-2010:234 2010-11-15
Mandriva MDVSA-2010:233 2010-11-15
Mandriva MDVSA-2010:232 2010-11-15
CentOS CESA-2010:0490 2010-08-16
Fedora FEDORA-2010-10101 2010-06-21
CentOS CESA-2010:0490 2010-07-21
Pardus 2010-95 2010-07-08
Fedora FEDORA-2010-10066 2010-06-21
Ubuntu USN-952-1 2010-06-21
CentOS CESA-2010:0490 2010-06-19
Red Hat RHSA-2010:0490-01 2010-06-17
Fedora FEDORA-2010-10388 2010-06-25
Slackware SSA:2010-176-05 2010-06-28

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds