Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.50666
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2003:001 (cups)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to cups
announced via advisory MDKSA-2003:001.

iDefense reported several security problems in CUPS that can
lead to local and remote root compromise. An integer overflow
in the HTTP interface can be used to gain remote access with
CUPS privilege. A local file race condition can be used to
gain root privilege, although the previous bug must be exploited
first. An attacker can remotely add printers to the vulnerable
system. A remote DoS can be accomplished due to negative length
in the memcpy() call. An integer overflow in image handling code
can be used to gain higher privilege. An attacker can gain local
root privilege due to a buffer overflow of the 'options' buffer.
A design problem can be exploited to gain local root access,
however this needs an added printer (which can also be done, as
per a previously noted bug). Wrong handling of zero-width images
can be abused to gain higher privilege. Finally, a file descriptor
leak and DoS due to missing checks of return values of file/socket
operations.

MandrakeSoft recommends all users upgrade these CUPS packages
immediately.

Affected versions: 7.2, 8.0, 8.1, 8.2, 9.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2003:001
http://www.idefense.com/advisory/12.23.02.txt

Risk factor : High

CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.