Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE: 2015:1041-1 Critical: Cups Security Issues Resolved

suse
Calendar Grey June 11, 2015
Dist Suse Esm H88
Essential SUSE patch for cups addresses numerous significant vulnerabilities, enhancing the security of impacted distributions.
An update that fixes three vulnerabilities is now available

Summary

The following issues are fixed by this update: * CVE-2012-5519: privilege escalation via cross-site scripting and bad print job submission used to replace cupsd.conf on server (bsc#924208). * CVE-2015-1158: Improper Update of Reference Count * CVE-2015-1159: Cross-Site Scripting Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12: zypper in -t patch SUSE-SLE-SDK-12-2015-264=1 - SUSE Linux Enterprise Server 12: zypper in -t patch SUSE-SLE-SERVER-12-2015-264=1 - SUSE Linux Enterprise Desktop 12: zypper in -t patch SUSE-SLE-DESKTOP-12-2015-264=1 To bring your system up-to-date, use "zypper patch". Package List:

References

#924208

Cross- CVE-2012-5519 CVE-2015-1158 CVE-2015-1159

Affected Products:

SUSE Linux Enterprise Software Development Kit 12

SUSE Linux Enterprise Server 12

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2012-5519.html

https://www.suse.com/security/cve/CVE-2015-1158.html

https://www.suse.com/security/cve/CVE-2015-1159.html

https://bugzilla.suse.com/show_bug.cgi?id=924208

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1041-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here