Debian Security Advisory
DSA-2990-1 cups -- security update
- Date Reported:
- 27 Jul 2014
- Affected Packages:
- cups
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2014-3537, CVE-2014-5029, CVE-2014-5030, CVE-2014-5031.
- More information:
-
It was discovered that the web interface in CUPS, the Common UNIX Printing System, incorrectly validated permissions on rss files and directory index files. A local attacker could possibly use this issue to bypass file permissions and read arbitrary files, possibly leading to a privilege escalation.
For the stable distribution (wheezy), these problems have been fixed in version 1.5.3-5+deb7u4.
For the unstable distribution (sid), these problems have been fixed in version 1.7.4-2.
We recommend that you upgrade your cups packages.