CUPS < 1.6.2 Multiple Vulnerabilities

This script is Copyright (C) 2013-2014 Tenable Network Security, Inc.


Synopsis :

The remote print service is potentially affected by multiple
vulnerabilities.

Description :

According to its banner, the version of CUPS installed on the remote
host is earlier than 1.6.2. It is, therefore, potentially affected by
the following vulnerabilities :

- Permissions on the file '/var/run/cups/certs/0' could
allow access to CUPS administration interface
authentication key material and thus, the interface
itself with admin rights. Additionally, users with admin
rights can edit the configuration file and specify
malicious commands that are then carried out with root
user permissions. (CVE-2012-5519)

- Multiple errors exist related to the functions
'ippEnumString', 'ippReadIO', 'set_time',
'load_request_root' and 'http_resolve_cb' that could
allow denial of service attacks.

See also :

http://cups.org/articles.php?L689
http://cups.org/str.php?L4223
http://cups.org/str.php?L4242
http://www.openwall.com/lists/oss-security/2012/11/11/2
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=692791

Solution :

Upgrade to CUPS version 1.6.2 or later, or apply the vendor patch.

Risk factor :

High / CVSS Base Score : 7.2
(CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 6.3
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: Misc.

Nessus Plugin ID: 65970 ()

Bugtraq ID: 56494

CVE ID: CVE-2012-5519