CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
Percentile
82.4%
Issue Overview:
A cross-site scripting (XSS) flaw was found in the CUPS web interface. An attacker could use this flaw to perform a cross-site scripting attack against users of the CUPS web interface. (CVE-2014-2856)
It was discovered that CUPS allowed certain users to create symbolic links in certain directories under /var/cache/cups/. A local user with the ‘lp’ group privileges could use this flaw to read the contents of arbitrary files on the system or, potentially, escalate their privileges on the system. (CVE-2014-3537, CVE-2014-5029, CVE-2014-5030, CVE-2014-5031)
Affected Packages:
cups
Issue Correction:
Run yum update cups to update your system.
New Packages:
i686:
cups-libs-1.4.2-67.20.al12.i686
cups-lpd-1.4.2-67.20.al12.i686
cups-devel-1.4.2-67.20.al12.i686
cups-php-1.4.2-67.20.al12.i686
cups-1.4.2-67.20.al12.i686
cups-debuginfo-1.4.2-67.20.al12.i686
src:
cups-1.4.2-67.20.al12.src
x86_64:
cups-lpd-1.4.2-67.20.al12.x86_64
cups-devel-1.4.2-67.20.al12.x86_64
cups-libs-1.4.2-67.20.al12.x86_64
cups-debuginfo-1.4.2-67.20.al12.x86_64
cups-1.4.2-67.20.al12.x86_64
cups-php-1.4.2-67.20.al12.x86_64
Red Hat: CVE-2014-2856, CVE-2014-3537, CVE-2014-5029, CVE-2014-5030, CVE-2014-5031
Mitre: CVE-2014-2856, CVE-2014-3537, CVE-2014-5029, CVE-2014-5030, CVE-2014-5031
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Amazon Linux | any | i686 | cups-libs | < 1.4.2-67.20.al12 | cups-libs-1.4.2-67.20.al12.i686.rpm |
Amazon Linux | any | i686 | cups-lpd | < 1.4.2-67.20.al12 | cups-lpd-1.4.2-67.20.al12.i686.rpm |
Amazon Linux | any | i686 | cups-devel | < 1.4.2-67.20.al12 | cups-devel-1.4.2-67.20.al12.i686.rpm |
Amazon Linux | any | i686 | cups-php | < 1.4.2-67.20.al12 | cups-php-1.4.2-67.20.al12.i686.rpm |
Amazon Linux | any | i686 | cups | < 1.4.2-67.20.al12 | cups-1.4.2-67.20.al12.i686.rpm |
Amazon Linux | any | i686 | cups-debuginfo | < 1.4.2-67.20.al12 | cups-debuginfo-1.4.2-67.20.al12.i686.rpm |
Amazon Linux | any | x86_64 | cups-lpd | < 1.4.2-67.20.al12 | cups-lpd-1.4.2-67.20.al12.x86_64.rpm |
Amazon Linux | any | x86_64 | cups-devel | < 1.4.2-67.20.al12 | cups-devel-1.4.2-67.20.al12.x86_64.rpm |
Amazon Linux | any | x86_64 | cups-libs | < 1.4.2-67.20.al12 | cups-libs-1.4.2-67.20.al12.x86_64.rpm |
Amazon Linux | any | x86_64 | cups-debuginfo | < 1.4.2-67.20.al12 | cups-debuginfo-1.4.2-67.20.al12.x86_64.rpm |