cups-filters 'OPVPWrapper::loadDriver()' Function Local Arbitrary Command Execution Vulnerability
BID:66158
Info
cups-filters 'OPVPWrapper::loadDriver()' Function Local Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 66158 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-6476 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 12 2014 12:00AM |
| Updated: | Mar 19 2015 08:28AM |
| Credit: | Murray McAllister |
| Vulnerable: |
Ubuntu Ubuntu Linux 10.04 LTS Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
cups-filters 'OPVPWrapper::loadDriver()' Function Local Arbitrary Command Execution Vulnerability
cups-filters is prone to a local arbitrary command-execution vulnerability.
A local attacker can exploit this issue to execute arbitrary commands with the privileges of the 'lp' user.
cups-filters is prone to a local arbitrary command-execution vulnerability.
A local attacker can exploit this issue to execute arbitrary commands with the privileges of the 'lp' user.
Exploit / POC
cups-filters 'OPVPWrapper::loadDriver()' Function Local Arbitrary Command Execution Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
cups-filters 'OPVPWrapper::loadDriver()' Function Local Arbitrary Command Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
cups-filters 'OPVPWrapper::loadDriver()' Function Local Arbitrary Command Execution Vulnerability
References:
References:
- cups-filters Homepage (linuxfoundation)
- Bug 1027551 - (CVE-2013-6476) CVE-2013-6476 cups-filters: pdftoopvp could load d (redhat)