Ubuntu Security Update USN-6844-2: CUPS regression

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,872
Reaction score
74
Credits
-1,257
USN-6844-1 fixed vulnerabilities in the CUPS package. The update lead to the discovery of a regression in CUPS with regards to how the cupsd daemon handles Listen configuration directive. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Rory McNamara discovered that when starting the cupsd server with a Listen configuration item, the cupsd process fails to validate if bind call passed. An attacker could possibly trick cupsd to perform an arbitrary chmod of the provided argument, providing world-writable access to the target.

Continue reading...
 


Follow Linux.org

Members online


Top