Easy Software Products CUPS访问控制列表绕过漏洞

漏洞信息详情

Easy Software Products CUPS访问控制列表绕过漏洞

漏洞简介

CUPS 1.1.21rc1以前版本将cupsd.conf的Location指令作为敏感情况。攻击者可以借助包含大写或小写字母的打印机名称绕过预定ACLs,该打印机名称与指令中指明的不同。

漏洞公告

The vendor has released a fixed version of the affected software to address this issue.
Please see the referenced advisories for more information.
Easy Software Products CUPS 1.0.4 -8

Easy Software Products CUPS 1.0.4

Easy Software Products CUPS 1.1.1

Easy Software Products CUPS 1.1.10

Easy Software Products CUPS 1.1.12

Easy Software Products CUPS 1.1.13

Easy Software Products CUPS 1.1.14

Easy Software Products CUPS 1.1.15

Easy Software Products CUPS 1.1.16

Easy Software Products CUPS 1.1.17

Easy Software Products CUPS 1.1.18

Easy Software Products CUPS 1.1.19

参考网址

来源: www.cups.org
链接:http://www.cups.org/str.php?L700

来源: bugzilla.redhat.com
链接:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162405

来源: OVAL
名称: oval:org.mitre.oval:def:9940
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9940

来源: FEDORA
名称: FLSA:163274
链接:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163274

来源: UBUNTU
名称: USN-185-1
链接:http://www.ubuntu.com/usn/usn-185-1

来源: REDHAT
名称: RHSA-2005:571
链接:http://www.redhat.com/support/errata/RHSA-2005-571.html

来源: SUSE
名称: SUSE-SR:2005:018
链接:http://www.novell.com/linux/security/advisories/2005_18_sr.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享