Bug 1096406 - (CVE-2018-4181) VUL-0: CVE-2018-4181: cups: Limited Local File Reads as Root via cupsd.conf Include Directive
(CVE-2018-4181)
VUL-0: CVE-2018-4181: cups: Limited Local File Reads as Root via cupsd.conf I...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Johannes Meixner
Security Team bot
https://smash.suse.de/issue/207575/
CVSSv3:SUSE:CVE-2018-4181:3.3:(AV:L/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-06-07 08:07 UTC by Andreas Stieger
Modified: 2020-06-15 13:28 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 14 Swamp Workflow Management 2018-07-27 12:51:48 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2018-08-10.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/64094
Comment 16 Swamp Workflow Management 2018-08-01 16:11:48 UTC
SUSE-SU-2018:2162-1: An update that solves 5 vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 1050082,1061066,1087018,1096405,1096406,1096407,1096408
CVE References: CVE-2017-18248,CVE-2018-4180,CVE-2018-4181,CVE-2018-4182,CVE-2018-4183
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    cups-1.7.5-20.14.1
SUSE Linux Enterprise Server 12-SP3 (src):    cups-1.7.5-20.14.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    cups-1.7.5-20.14.1
Comment 17 Swamp Workflow Management 2018-08-02 16:09:03 UTC
SUSE-SU-2018:2172-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1096405,1096406,1096407,1096408
CVE References: CVE-2018-4180,CVE-2018-4181,CVE-2018-4182,CVE-2018-4183
Sources used:
SUSE Linux Enterprise Module for Development Tools 15 (src):    cups-2.2.7-3.3.1
SUSE Linux Enterprise Module for Desktop Applications 15 (src):    cups-2.2.7-3.3.1
SUSE Linux Enterprise Module for Basesystem 15 (src):    cups-2.2.7-3.3.1
Comment 18 Swamp Workflow Management 2018-08-07 16:08:02 UTC
SUSE-SU-2018:2233-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1096405,1096406,1096407,1096408
CVE References: CVE-2018-4180,CVE-2018-4181,CVE-2018-4182,CVE-2018-4183
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    cups-1.3.9-8.46.56.3.1
SUSE Linux Enterprise Server 11-SP4 (src):    cups-1.3.9-8.46.56.3.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    cups-1.3.9-8.46.56.3.1
Comment 19 Swamp Workflow Management 2018-08-07 19:09:31 UTC
openSUSE-SU-2018:2239-1: An update that solves 5 vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 1050082,1061066,1087018,1096405,1096406,1096407,1096408
CVE References: CVE-2017-18248,CVE-2018-4180,CVE-2018-4181,CVE-2018-4182,CVE-2018-4183
Sources used:
openSUSE Leap 42.3 (src):    cups-1.7.5-12.6.1
Comment 20 Swamp Workflow Management 2018-08-10 01:13:13 UTC
openSUSE-SU-2018:2292-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1096405,1096406,1096407,1096408
CVE References: CVE-2018-4180,CVE-2018-4181,CVE-2018-4182,CVE-2018-4183
Sources used:
openSUSE Leap 15.0 (src):    cups-2.2.7-lp150.2.3.1
Comment 21 Johannes Meixner 2019-07-01 16:01:11 UTC
.