Lucene search

K
ubuntuUbuntuUSN-2341-1
HistorySep 08, 2014 - 12:00 a.m.

CUPS vulnerabilities

2014-09-0800:00:00
ubuntu.com
35

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.7

Confidence

High

EPSS

0.005

Percentile

77.0%

Releases

  • Ubuntu 14.04 ESM
  • Ubuntu 12.04
  • Ubuntu 10.04

Packages

  • cups - Common UNIX Printing System™

Details

Salvatore Bonaccorso discovered that the CUPS web interface incorrectly
validated permissions and incorrectly handled symlinks. An attacker could
possibly use this issue to bypass file permissions and read arbitrary
files, possibly leading to a privilege escalation.

OSVersionArchitecturePackageVersionFilename
Ubuntu14.04noarchcups< 1.7.2-0ubuntu1.2UNKNOWN
Ubuntu14.04noarchcups-bsd< 1.7.2-0ubuntu1.2UNKNOWN
Ubuntu14.04noarchcups-client< 1.7.2-0ubuntu1.2UNKNOWN
Ubuntu14.04noarchcups-core-drivers< 1.7.2-0ubuntu1.2UNKNOWN
Ubuntu14.04noarchcups-daemon< 1.7.2-0ubuntu1.2UNKNOWN
Ubuntu14.04noarchcups-dbg< 1.7.2-0ubuntu1.2UNKNOWN
Ubuntu14.04noarchcups-ppdc< 1.7.2-0ubuntu1.2UNKNOWN
Ubuntu14.04noarchlibcups2< 1.7.2-0ubuntu1.2UNKNOWN
Ubuntu14.04noarchlibcups2-dev< 1.7.2-0ubuntu1.2UNKNOWN
Ubuntu14.04noarchlibcupscgi1< 1.7.2-0ubuntu1.2UNKNOWN
Rows per page:
1-10 of 511

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.7

Confidence

High

EPSS

0.005

Percentile

77.0%