Boletines de Vulnerabilidades

DSA-2990 cups - security update


Información sobre el sistema

   
Software afectado Debian

Descripción

It was discovered that the web interface in CUPS, the Common UNIXPrinting System, incorrectly validated permissions on rss files anddirectory index files. A local attacker could possibly use this issueto bypass file permissions and read arbitrary files, possibly leadingto a privilege escalation.

More info:

https://www.debian.org/security/2014/dsa-2990

Identificadores estándar

Propiedad Valor
CVE CVE-2014-3537 ,CVE-2014-5029 ,CVE-2014-5030 ,CVE-2014-5031 and DSA-2990.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-07-30

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT