Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments

Partner Links
Website builder
WinWeb OnlineOffice
Shopping and price comparison with product reviews at dooyoo.co.uk

user friendly

CeBIT 2010

High-class talks around the clock in the Forum, non-commercial projects presenting their work, new developments at the largest IT fair in the world, CeBIT Open Source 2010 in Hanover, Germany.

Visit them in hall 2, March 2-6 or here.

  linux-magazine.com » Online » News » CUPS Print Server Vulnerabilities Removed  

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg

CUPS Print Server Vulnerabilities Removed

The new 1.3.7 is the CUPS developers have closed down several vulnerabilities in the popular print server.

On networks that ran CUPS as a print server, potential attackers could provoke a heap-based buffer overflow via the "cgiCompileSearch()" search function implemented by the CGI interface if the printer was shared. A carefully crafted search request was required to do this. The exploit gave attackers the ability to assumed the privileges of the user accounts running the service and to execute code. Security researchers iDefence discovered the vulnerability, which is classified as CVE ID CVE-2008-0047, in CUPS version 1.3.5, although older versions may also be affected.

This also applies to bug CVE-2008-1373 which was provoked by GIF image files. If image files had an invalid value in the "code_size" field, a buffer overflow could be provoked. The new release also removes a couple of minor errrors in CUPS. Check out the release notes for more details.

The new 1.3.7 version is now available for downloading. Distributors will be providing updated packages shortly.

(Jan Rähm)

Comments


Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg
Related Articles
Script Error Opens up Security Hole in Xen 3.0.3
Vulnerabilities in Xine-Lib and Mplayer
Vulnerability Discovered in X Font Server
Mozilla Developers Remove Critical Bugs
Holes in Firewall-1
Local Vulnerabilities in Current Kernels
Special Linux Magazine 3 for 1 Offer

Get 3 Issues + 3 DVDs for the price of a single issue!

Let Linux Magazine's hands-on, technical articles guide you in your daily Linux use. Check out bonus DVDs like Ubuntu, SUSE, or Fedora and save the download.

Only available for a limited time. Don't miss out!

more...

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2010 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux Technical Review]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland]
International: [Linux Magazine Brazil] [EasyLinux Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]