|
|
| |
|
| |
cups: unauthorized access to administration interface
| Package(s): | cups |
CVE #(s): | CVE-2012-6094
|
| Created: | January 7, 2013 |
Updated: | April 5, 2013 |
| Description: |
From the Mageia advisory:
During the process of CUPS socket activation code refactoring in
favor of systemd capability a security flaw was found in the way
CUPS service honored Listen localhost:631 cupsd.conf configuration
option. The setting was recognized properly for IPv4-enabled systems,
but failed to be correctly applied for IPv6-enabled systems. As a
result, a remote attacker could use this flaw to obtain (unauthorized)
access to the CUPS web-based administration interface. |
| Alerts: |
|
( Log in to post comments)
|
|
|