Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Scientific Linux: CVE-2010-2431 Critical CUPS Security Update Insight

Scientific Large Esm H446
Important: cups security update
Date: Fri, 29 Oct 2010 13:32:40 -0500
Reply-To: Troy Dawson 
Sender: Security Errata for Scientific Linux
 
From: Troy Dawson 
Subject: Security ERRATA Important: cups on SL5.x i386/x86_64
Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it."
 

Synopsis:	Important: cups security update
Issue date:	2010-10-28
CVE Names:	CVE-2010-2431 CVE-2010-2941

A use-after-free flaw was found in the way the CUPS server parsed
Internet Printing Protocol (IPP) packets. A malicious user able to send
IPP requests to the CUPS server could use this flaw to crash the CUPS
server or, potentially, execute arbitrary code with the privileges of
the CUPS server. (CVE-2010-2941)

A possible privilege escalation flaw was found in CUPS. An unprivileged
process running as the "lp" user (such as a compromised external filter
program spawned by the CUPS server) could trick the CUPS server into
overwriting arbitrary files as the root user. (CVE-2010-2431)

After installing this update, the cupsd daemon will be restarted
automatically.

SL 5.x

 SRPMS:
cups-1.3.7-18.el5_5.8.src.rpm
 i386:
cups-1.3.7-18.el5_5.8.i386.rpm
cups-devel-1.3.7-18.el5_5.8.i386.rpm
cups-libs-1.3.7-18.el5_5.8.i386.rpm
cups-lpd-1.3.7-18.el5_5.8.i386.rpm
 x86_64:
cups-1.3.7-18.el5_5.8.x86_64.rpm
cups-devel-1.3.7-18.el5_5.8.i386.rpm
cups-devel-1.3.7-18.el5_5.8.x86_64.rpm
cups-libs-1.3.7-18.el5_5.8.i386.rpm
cups-libs-1.3.7-18.el5_5.8.x86_64.rpm
cups-lpd-1.3.7-18.el5_5.8.x86_64.rpm

-Connie Sieh
-Troy Dawson