LWN.net Logo

cups: unauthorized access to administration interface

Package(s):cups CVE #(s):CVE-2012-6094
Created:January 7, 2013 Updated:April 5, 2013
Description: From the Mageia advisory:

During the process of CUPS socket activation code refactoring in favor of systemd capability a security flaw was found in the way CUPS service honored Listen localhost:631 cupsd.conf configuration option. The setting was recognized properly for IPv4-enabled systems, but failed to be correctly applied for IPv6-enabled systems. As a result, a remote attacker could use this flaw to obtain (unauthorized) access to the CUPS web-based administration interface.

Alerts:
Mageia MGASA-2013-0004 2013-01-06
Fedora FEDORA-2012-19606 2013-02-26
Mandriva MDVSA-2013:034 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds