Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

SUSE: 2020:5678-1 High: apache256 Security Vulnerability Patch

suse
Calendar Grey June 11, 2015
Dist Suse Esm H88
SUSE Security Alert addressing serious vulnerabilities in cups154. Safeguard your system and remain current with update information.
An update that fixes three vulnerabilities is now available

Summary

The following issues are fixed by this update: * CVE-2012-5519: privilege escalation via cross-site scripting and bad print job submission used to replace cupsd.conf on server (bsc#924208). * CVE-2015-1158: Improper Update of Reference Count * CVE-2015-1159: Cross-Site Scripting Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Legacy Software 12: zypper in -t patch SUSE-SLE-Module-Legacy-12-2015-265=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Module for Legacy Software 12 (ppc64le x86_64): cups154-1.5.4-9.1 cups154-client-1.5.4-9.1 cups154-client-debuginfo-1.5.4-9.1 cups154-debuginfo-1.5.4-9.1

References

#924208

Cross- CVE-2012-5519 CVE-2015-1158 CVE-2015-1159

Affected Products:

SUSE Linux Enterprise Module for Legacy Software 12

https://www.suse.com/security/cve/CVE-2012-5519.html

https://www.suse.com/security/cve/CVE-2015-1158.html

https://www.suse.com/security/cve/CVE-2015-1159.html

https://bugzilla.suse.com/show_bug.cgi?id=924208

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1044-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here