Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Date: Fri, 29 Oct 2010 13:32:40 -0500 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Important: cups on SL5.x i386/x86_64 Comments: To: " This email address is being protected from spambots. You need JavaScript enabled to view it. "Synopsis: Important: cups security update Issue date: 2010-10-28 CVE Names: CVE-2010-2431 CVE-2010-2941 A use-after-free flaw was found in the way the CUPS server parsed Internet Printing Protocol (IPP) packets. A malicious user able to send IPP requests to the CUPS server could use this flaw to crash the CUPS server or, potentially, execute arbitrary code with the privileges of the CUPS server. (CVE-2010-2941) A possible privilege escalation flaw was found in CUPS. An unprivileged process running as the "lp" user (such as a compromised external filter program spawned by the CUPS server) could trick the CUPS server into overwriting arbitrary files as the root user. (CVE-2010-2431) After installing this update, the cupsd daemon will be restarted automatically. SL 5.x SRPMS: cups-1.3.7-18.el5_5.8.src.rpm i386: cups-1.3.7-18.el5_5.8.i386.rpm cups-devel-1.3.7-18.el5_5.8.i386.rpm cups-libs-1.3.7-18.el5_5.8.i386.rpm cups-lpd-1.3.7-18.el5_5.8.i386.rpm x86_64: cups-1.3.7-18.el5_5.8.x86_64.rpm cups-devel-1.3.7-18.el5_5.8.i386.rpm cups-devel-1.3.7-18.el5_5.8.x86_64.rpm cups-libs-1.3.7-18.el5_5.8.i386.rpm cups-libs-1.3.7-18.el5_5.8.x86_64.rpm cups-lpd-1.3.7-18.el5_5.8.x86_64.rpm -Connie Sieh -Troy Dawson