Lucene search

K
osvGoogleOSV:DSA-2176-1
HistoryMar 02, 2011 - 12:00 a.m.

cups - several

2011-03-0200:00:00
Google
osv.dev
10

0.691 Medium

EPSS

Percentile

98.0%

Several vulnerabilities have been discovered in the Common UNIX Printing
System:

  • CVE-2008-5183
    A null pointer dereference in RSS job completion notifications
    could lead to denial of service.
  • CVE-2009-3553
    It was discovered that incorrect file descriptor handling
    could lead to denial of service.
  • CVE-2010-0540
    A cross-site request forgery vulnerability was discovered in
    the web interface.
  • CVE-2010-0542
    Incorrect memory management in the filter subsystem could lead
    to denial of service.
  • CVE-2010-1748
    Information disclosure in the web interface.
  • CVE-2010-2431
    Emmanuel Bouillon discovered a symlink vulnerability in handling
    of cache files.
  • CVE-2010-2432
    Denial of service in the authentication code.
  • CVE-2010-2941
    Incorrect memory management in the IPP code could lead to denial
    of service or the execution of arbitrary code.

For the oldstable distribution (lenny), this problem has been fixed in
version 1.3.8-1+lenny9.

The stable distribution (squeeze) and the unstable distribution (sid)
had already been fixed prior to the initial Squeeze release.

We recommend that you upgrade your cups packages.