Описание
Security update for cups
This update for cups fixes the following issues:
The following security vulnerabilities were fixed:
- CVE-2017-18248: Handle invalid characters properly in printing jobs. This fixes a problem that was causing the DBUS library to abort the calling process. (bsc#1061066 bsc#1087018)
- Fixed a local privilege escalation to root and sandbox bypasses in the scheduler
- CVE-2018-4180: Fixed a local privilege escalation to root in dnssd backend (bsc#1096405)
- CVE-2018-4181: Limited local file reads as root via cupsd.conf include directive (bsc#1096406)
- CVE-2018-4182: Fixed a sandbox bypass due to insecure error handling (bsc#1096407)
- CVE-2018-4183: Fixed a sandbox bypass due to profile misconfiguration (bsc#1096408)
The following other issue was fixed:
- Fixed authorization check for clients (like samba) connected through the local socket when Kerberos authentication is enabled (bsc#1050082)
Список пакетов
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Software Development Kit 12 SP3
Ссылки
- Link for SUSE-SU-2018:2162-1
- E-Mail link for SUSE-SU-2018:2162-1
- SUSE Security Ratings
- SUSE Bug 1050082
- SUSE Bug 1061066
- SUSE Bug 1087018
- SUSE Bug 1096405
- SUSE Bug 1096406
- SUSE Bug 1096407
- SUSE Bug 1096408
- SUSE CVE CVE-2017-18248 page
- SUSE CVE CVE-2018-4180 page
- SUSE CVE CVE-2018-4181 page
- SUSE CVE CVE-2018-4182 page
- SUSE CVE CVE-2018-4183 page
Описание
The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.
Затронутые продукты
Ссылки
- CVE-2017-18248
- SUSE Bug 1087018
- SUSE Bug 1087072
Описание
In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
Затронутые продукты
Ссылки
- CVE-2018-4180
- SUSE Bug 1096405
- SUSE Bug 1096408
Описание
In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
Затронутые продукты
Ссылки
- CVE-2018-4181
- SUSE Bug 1096406
- SUSE Bug 1096408
- SUSE Bug 1105281
Описание
In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restrictions on CUPS.
Затронутые продукты
Ссылки
- CVE-2018-4182
- SUSE Bug 1096407
- SUSE Bug 1096408
- SUSE Bug 1105281
- SUSE Bug 1217278
Описание
In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restrictions.
Затронутые продукты
Ссылки
- CVE-2018-4183
- SUSE Bug 1096407
- SUSE Bug 1096408