Bug 680210 - VUL-1: cups: local file overwrite with users in "lp" group via /var/cache/cups/
VUL-1: cups: local file overwrite with users in "lp" group via /var/cache/cups/
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: General
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
maint:released:sle10-sp4:43333 maint:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2011-03-16 16:25 UTC by Marcus Meissner
Modified: 2018-10-19 18:08 UTC (History)
2 users (show)

See Also:
Found By: Customer
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2011-03-16 16:25:20 UTC
is public, from cve db

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2431

The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file. 



Please note that our users are not added to the "lp" group by default, which is required as precondition of this issue.
Comment 1 Marcus Meissner 2011-03-16 16:35:20 UTC
if an attacker gains access via a explioit to the "lp" group, it however is possible to hop further with this hole.
Comment 2 Johannes Meixner 2011-03-17 10:29:27 UTC
The matching CUPS STR for CVE-2010-2431 is
http://cups.org/str.php?L3510

openSUSE 11.4 has cups-1.4.6 which is safe
openSUSE 11.3 has cups-1.4.4 which is safe

openSUSE 11.2 has cups-1.3.11
SLE11 has cups-1.3.9
SLE10 has cups-1.1.23
SLE9 has cups-1.1.20
Comment 3 Swamp Workflow Management 2011-07-05 11:42:40 UTC
The SWAMPID for this issue is 42066.
This issue was rated as low.
Please submit fixed packages until 2011-08-02.
Also create a patchinfo file using this link:
https://swamp.suse.de/webswamp/wf/42066
Comment 13 Sebastian Krahmer 2011-10-17 09:30:16 UTC
done
Comment 14 Sebastian Krahmer 2011-10-17 09:31:03 UTC
.
Comment 15 Swamp Workflow Management 2011-10-17 12:58:27 UTC
Update released for: cups, cups-client, cups-debuginfo, cups-devel, cups-libs, cups-libs-32bit, cups-libs-64bit, cups-libs-x86
Products:
SLE-DESKTOP 10-SP4 (i386, x86_64)
SLE-SERVER 10-SP4 (i386, ia64, ppc, s390x, x86_64)
Comment 16 Swamp Workflow Management 2011-10-17 20:00:46 UTC
Update released for: cups, cups-client, cups-debuginfo, cups-debugsource, cups-devel, cups-libs, cups-libs-32bit, cups-libs-x86
Products:
SLE-DEBUGINFO 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-DESKTOP 11-SP1 (i386, x86_64)
SLE-SDK 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP1-TERADATA (x86_64)
SLES4VMWARE 11-SP1 (i386, x86_64)
Comment 17 Swamp Workflow Management 2011-10-17 20:11:07 UTC
Update released for: cups, cups-client, cups-debuginfo, cups-devel, cups-libs, cups-libs-32bit, cups-libs-64bit, cups-libs-x86
Products:
SLE-SAP-APL 10-SP3 (x86_64)
SLE-SERVER 10-SP3 (i386, ia64, ppc, s390x, x86_64)
SLE-SERVER 10-SP3-TERADATA (x86_64)