Lucene search

K
mageiaGentoo FoundationMGASA-2014-0021
HistoryJan 21, 2014 - 8:19 p.m.

Updated cups packages fix a security vulverability

2014-01-2120:19:37
Gentoo Foundation
advisories.mageia.org
16

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:H/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%

Updated cups packages fix security vulnerability: Jann Horn discovered that the CUPS lppasswd tool incorrectly read a user configuration file in certain configurations. A local attacker could use this to read sensitive information from certain files, bypassing access restrictions (CVE-2013-6891).

OSVersionArchitecturePackageVersionFilename
Mageia3noarchcups< 1.5.4-9.1cups-1.5.4-9.1.mga3

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:H/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%