USN-2172-1: CUPS vulnerability

Publication date

24 April 2014

Overview

CUPS could be made to expose sensitive information over the network.


Packages

  • cups - Common UNIX Printing System(tm)

Details

Alex Korobkin discovered that the CUPS web interface incorrectly protected
against cross-site scripting (XSS) attacks. If an authenticated user were
tricked into visiting a malicious website while logged into CUPS, a remote
attacker could modify the CUPS configuration and possibly steal
confidential data.

Alex Korobkin discovered that the CUPS web interface incorrectly protected
against cross-site scripting (XSS) attacks. If an authenticated user were
tricked into visiting a malicious website while logged into CUPS, a remote
attacker could modify the CUPS configuration and possibly steal
confidential data.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
13.10 saucy cups –  1.7.0~rc1-0ubuntu5.3
12.10 quantal cups –  1.6.1-0ubuntu11.6
12.04 precise cups –  1.5.3-0ubuntu8.2
10.04 lucid cups –  1.4.3-1ubuntu1.11

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›