[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2014-438 ---- cups

ID: oval:org.secpod.oval:def:1600019Date: (C)2016-01-19   (M)2023-02-20
Class: PATCHFamily: unix




A cross-site scripting flaw was found in the CUPS web interface. An attacker could use this flaw to perform a cross-site scripting attack against users of the CUPS web interface. It was discovered that CUPS allowed certain users to create symbolic links in certain directories under /var/cache/cups/. A local user with the "lp" group privileges could use this flaw to read the contents of arbitrary files on the system or, potentially, escalate their privileges on the system

Platform:
Amazon Linux AMI
Product:
cups
Reference:
ALAS-2014-438
CVE-2014-3537
CVE-2014-2856
CVE-2014-5029
CVE-2014-5030
CVE-2014-5031
CVE    5
CVE-2014-2856
CVE-2014-3537
CVE-2014-5031
CVE-2014-5030
...
CPE    2
cpe:/o:amazon:linux
cpe:/a:cups:cups

© SecPod Technologies