PT-2014-1813 · Openprinting+3 · Cups-Filters+3

Johannes Meixner

·

Published

2014-05-08

·

Updated

2024-06-15

·

CVE-2014-4338

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions cups-filters versions 1.0.35 through 1.0.52
Description The issue allows remote attackers to bypass intended access restrictions by leveraging a malformed cups-browsed.conf BrowseAllow directive. This can lead to a disruption of protected information. The exploitation of the vulnerabilities can be carried out remotely.
Recommendations For versions 1.0.35 through 1.0.52, update to version 1.0.53 or later to resolve the issue. As a temporary workaround, consider restricting access to the cups-browsed.conf file until a patch is available. Avoid using a malformed BrowseAllow directive in the cups-browsed.conf file to prevent bypassing intended access restrictions.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1665
BDU:2015-06081
BDU:2015-06082
BDU:2015-06083
BDU:2015-06084
BDU:2015-09199
BDU:2015-09200
BDU:2015-09201
BDU:2015-09202
CESA-2014_1795
CVE-2014-4338
MGASA-2014-0267
OPENSUSE-SU-2024:10313-1
RHSA-2014:1795
RHSA-2014_1795
USN-2210-1

Affected Products

Alt Linux
Centos
Red Hat
Cups-Filters