Vulnerability Bulletins

DSA-2990 cups - security update

   
Affected software Debian
 
It was discovered that the web interface in CUPS, the Common UNIXPrinting System, incorrectly validated permissions on rss files anddirectory index files. A local attacker could possibly use this issueto bypass file permissions and read arbitrary files, possibly leadingto a privilege escalation.

More info:

https://www.debian.org/security/2014/dsa-2990