Debian Security Advisory
DLA-0022-1 cups -- LTS security update
- Date Reported:
- 31 Jul 2014
- Affected Packages:
- cups
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2014-3537, CVE-2014-5029, CVE-2014-5030, CVE-2014-5031.
- More information:
-
It was discovered that the web interface in CUPS, the Common UNIX Printing System, incorrectly validated permissions on rss files and directory index files. A local attacker could possibly use this issue to bypass file permissions and read arbitrary files, possibly leading to a privilege escalation.
For Debian 6
Squeeze
, these issues have been fixed in cups version 1.4.4-7+squeeze6