Spotlight | Reviews | Current Issue | Academy | Newsletter | Subscribe | Shop |
Departments

Partner Links
Make your own website
WinWeb OnlineOffice
Comparing prices of hardware is worth it.
Price Comparison
UK Linux Jobs
What:
Where:
Country:
vacatures Netherlands njobs Linux vacatures
arbeit Deutschland njobs Linux arbeit
work United Kingdom njobs Linux jobs
Lavoro Italia njobs Linux lavoro
Emploi France njobs Linux emploi
trabajo Espana njobs Linux trabajo

user friendly

Admin Magazine

ADMIN Network & Security

Subscribe now and save!

ADMIN - Explore the new world of system administration! Special introductory offer! Order by September 30th to save 10% off the regular subscription price! Each issue delivers technical solutions to the real-world problems you face every day. Learn the latest techniques for better:

  • network security
  • system management
  • troubleshooting
  • performance tuning
  • virtualization
  • cloud computing

 

on Windows, Linux, Solaris, and popular varieties of Unix.

http://www.admin-magazine.com/

  linux-magazine.com » Online » News » CUPS Print Server Vulnerabilities Removed  

Print this page. Recommend
Share

CUPS Print Server Vulnerabilities Removed

The new 1.3.7 is the CUPS developers have closed down several vulnerabilities in the popular print server.

On networks that ran CUPS as a print server, potential attackers could provoke a heap-based buffer overflow via the "cgiCompileSearch()" search function implemented by the CGI interface if the printer was shared. A carefully crafted search request was required to do this. The exploit gave attackers the ability to assumed the privileges of the user accounts running the service and to execute code. Security researchers iDefence discovered the vulnerability, which is classified as CVE ID CVE-2008-0047, in CUPS version 1.3.5, although older versions may also be affected.

This also applies to bug CVE-2008-1373 which was provoked by GIF image files. If image files had an invalid value in the "code_size" field, a buffer overflow could be provoked. The new release also removes a couple of minor errrors in CUPS. Check out the release notes for more details.

The new 1.3.7 version is now available for downloading. Distributors will be providing updated packages shortly.

(Jan Rähm)

Comments


Print this page. Recommend
Share
Related Articles
Script Error Opens up Security Hole in Xen 3.0.3
Vulnerabilities in Xine-Lib and Mplayer
Vulnerability Discovered in X Font Server
Mozilla Developers Remove Critical Bugs
Holes in Firewall-1
Local Vulnerabilities in Current Kernels
Rikki's Open Source Exchange

Stop by Rikki's Open Source Exchange for dispatches from the world of women in open source.

Rikki Kite examines the experience of women across the spectrum of open source –
the people, projects, organizations, events, articles, issues, and news.

more...