openSUSE Security Update : cups (openSUSE-2015-418)

This script is Copyright (C) 2015 Tenable Network Security, Inc.


Synopsis :

The remote openSUSE host is missing a security update.

Description :

This update fixes the following issues :

- CVE-2015-1158 and CVE-2015-1159 fixes a possible
privilege escalation via cross-site scripting and bad
print job submission used to replace cupsd.conf on
server (CUPS STR#4609 CERT-VU-810572 CVE-2015-1158
CVE-2015-1159 bugzilla.suse.com bsc#924208). In general
it is crucial to limit access to CUPS to trustworthy
users who do not misuse their permission to submit print
jobs which means to upload arbitrary data onto the CUPS
server, see
https://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_setti
ngs and cf. the entries about CVE-2012-5519 below.

See also :

https://bugzilla.opensuse.org/show_bug.cgi?id=924208
https://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_settings

Solution :

Update the affected cups packages.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)

Family: SuSE Local Security Checks

Nessus Plugin ID: 84184 ()

Bugtraq ID:

CVE ID: CVE-2012-5519
CVE-2015-1158
CVE-2015-1159

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now