cups-filters CVE-2014-4338 Security Bypass Vulnerability
BID:68124
Info
cups-filters CVE-2014-4338 Security Bypass Vulnerability
| Bugtraq ID: | 68124 |
| Class: | Design Error |
| CVE: |
CVE-2014-4338 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2014 12:00AM |
| Updated: | Dec 08 2015 10:15PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Oracle Enterprise Linux 7 Linuxfoundation cups-filters 1.0.51 Linuxfoundation cups-filters 1.0.5 Linuxfoundation cups-filters 1.0.50 |
| Not Vulnerable: |
Linuxfoundation cups-filters 1.0.53 |
Discussion
cups-filters CVE-2014-4338 Security Bypass Vulnerability
cups-filters is prone to a security-bypass vulnerability because it fails to adequately handle user-supplied input.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks.
cups-filters is prone to a security-bypass vulnerability because it fails to adequately handle user-supplied input.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks.
Exploit / POC
cups-filters CVE-2014-4338 Security Bypass Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
cups-filters CVE-2014-4338 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
cups-filters CVE-2014-4338 Security Bypass Vulnerability
References:
References:
- Bug 1204 - cups-browsed: unsupported BrowseAllow value lets cups-browsed accept (Linux foundation)
- cups-filters Homepage (linuxfoundation)