Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: 2010-49: Cups: Privilege Escalation
Posted by Benjamin D. Thomas
A vulnerability has been fixed in Cups, which can be exploited by malicious people to gain certain privileges.
------------------------------------------------------------------------
Pardus Linux Security Advisory 2010-49 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2010-04-09
Severity: 3
Type: Local
------------------------------------------------------------------------
Summary
======
A vulnerability has been fixed in Cups, which can be exploited by
malicious people to gain certain privileges.
Description
==========
CVE-2010-0393:
The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS
relies on an environment variable to determine the file that provides
localized message strings, which allows local users to gain privileges
via a file that contains crafted localization data with format string
specifiers.
Affected packages:
Pardus 2008:
cups, all before 1.3.10-60-13
Resolution
=========
There are update(s) for cups. You can update them via Package Manager or
with a single command from console:
pisi up cups
References
=========
* http://bugs.pardus.org.tr/show_bug.cgi?id438
* http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0393
* https://bugzilla.redhat.com/show_bug.cgi?idU8460
------------------------------------------------------------------------