Oval Definition:oval:org.mitre.oval:def:28375
Revision Date:2015-01-26Version:8
Title:RHSA-2014:1795 -- cups-filters security update (Moderate)
Description:The cups-filters package contains backends, filters, and other softwarethat was once part of the core CUPS distribution but is now maintainedindependently.An out-of-bounds read flaw was found in the way the process_browse_data()function of cups-browsed handled certain browse packets. A remote attackercould send a specially crafted browse packet that, when processed bycups-browsed, would crash the cups-browsed daemon. (CVE-2014-4337)A flaw was found in the way the cups-browsed daemon interpreted the"BrowseAllow" directive in the cups-browsed.conf file. An attacker able toadd a malformed "BrowseAllow" directive to the cups-browsed.conf file coulduse this flaw to bypass intended access restrictions. (CVE-2014-4338)All cups-filters users are advised to upgrade to these updated packages,which contain backported patches to correct these issues. After installingthis update, the cups-browsed daemon will be restarted automatically.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2014:1795
CVE-2014-4337
CVE-2014-4338
RHSA-2014:1795
Platform(s):CentOS Linux 7
Red Hat Enterprise Linux 7
Product(s):cups-filters
Definition Synopsis
  • Red Hat Enterprise Linux 7 and CentOS Linux 7 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 7
  • OR The operating system installed on the system is CentOS Linux 7.x
  • AND Packages match section
  • cups-filters is earlier than 0:1.0.35-15.el7_0.1
  • OR cups-filters-devel is earlier than 0:1.0.35-15.el7_0.1
  • OR cups-filters-libs is earlier than 0:1.0.35-15.el7_0.1
  • Red Hat Enterprise Linux 7 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 7
  • AND cups-filters-debuginfo is earlier than 0:1.0.35-15.el7_0.1
  • BACK