Mageia alert MGASA-2015-0132 (cups-filters)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2015-0132: Updated cups-filters packages fix CVE-2015-2265 | |
| Date: | Sat, 4 Apr 2015 12:46:19 +0200 | |
| Message-ID: | <20150404104619.2635E41995@valstar.mageia.org> |
MGASA-2015-0132 - Updated cups-filters packages fix CVE-2015-2265 Publication date: 04 Apr 2015 URL: http://advisories.mageia.org/MGASA-2015-0132.html Type: security Affected Mageia releases: 4 CVE: CVE-2015-2265 Description: Updated cups-filters package fixes security vulnerability: cups-browsed in cups-filters before 1.0.66 contained a bug in the remove_bad_chars() function, where it failed to reliably filter out illegal characters if there were two or more subsequent illegal characters, allowing execution of arbitrary commands with the rights of the "lp" user, using forged print service announcements on DNS-SD servers (CVE-2015-2265). References: - https://bugs.mageia.org/show_bug.cgi?id=15424 - https://bugs.linuxfoundation.org/show_bug.cgi?id=1265 - http://www.ubuntu.com/usn/usn-2532-1/ - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2265 SRPMS: - 4/core/cups-filters-1.0.53-1.1.mga4
