|
|
Subscribe / Log in / New account

Mageia alert MGASA-2018-0147 (cups)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2018-0147: Updated cups packages fix security vulnerability
Date:  Tue, 27 Feb 2018 00:41:40 +0100
Message-ID:  <20180226234140.4BDFD9FDBA@duvel.mageia.org>

MGASA-2018-0147 - Updated cups packages fix security vulnerability Publication date: 26 Feb 2018 URL: https://advisories.mageia.org/MGASA-2018-0147.html Type: security Affected Mageia releases: 5 CVE: CVE-2017-18190 Description: Updated cups packages fix security vulnerability: Jann Horn discovered that CUPS permitted HTTP requests with the Host header set to "localhost.localdomain" from the loopback interface. If a user were tricked in to opening a specially crafted website in their web browser, an attacker could potentially exploit this to obtain sensitive information or control printers, via a DNS rebinding attack (CVE-2017-18190). References: - https://bugs.mageia.org/show_bug.cgi?id=22649 - https://usn.ubuntu.com/usn/usn-3577-1/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1... SRPMS: - 5/core/cups-2.0.4-1.4.mga5


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds