Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 519792 (CVE-2014-5030)

Summary: <net-print/cups-1.7.5: two vulnerabilities (CVE-2014-5030)
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: A4 [noglsa]
Package list:
Runtime testing required: ---
Bug Depends on: 513552    
Bug Blocks:    

Description Agostino Sarubbo gentoo-dev 2014-08-13 07:58:17 UTC
From https://bugzilla.redhat.com/show_bug.cgi?id=1128764:

It was reported [1] that CUPS allow local users to read arbitrary files via symlink attack on the 
directory index files:

index.html
index.class
index.pl
index.php
index.pyc
index.py

Upstream patches are available at [2] as well.

[1]: http://seclists.org/oss-sec/2014/q3/209
[2]: https://cups.org/str.php?L4455


From https://bugzilla.redhat.com/show_bug.cgi?id=1128767:

It was reported [1] that CUPS does not check that files have world-readable permissions, which 
allow to local users to obtain sensitive information.

Upstream patches are available at [2] as well.

[1]: http://seclists.org/oss-sec/2014/q3/209
[2]: https://cups.org/str.php?L4455


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2014-08-17 04:21:16 UTC
CVE-2014-5030 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-5030):
  CUPS before 2.0 allows local users to read arbitrary files via a symlink
  attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5)
  index.pyc, or (6) index.py.
Comment 2 Andreas K. Hüttel archtester gentoo-dev 2014-09-06 19:01:20 UTC
This is fixed in CUPS 1.7.5, which I just added to the tree. 
Let's wait a week and then stabilize it.
Comment 3 Andreas K. Hüttel archtester gentoo-dev 2014-09-10 18:18:38 UTC
I don't see any additional bug reports coming in from the 1.7.4 -> 1.7.5 update, so let's continue. 

Arches please fast-stabilize net-print/cups-1.7.5
Target: all stable arches
Comment 4 Jeroen Roovers (RETIRED) gentoo-dev 2014-09-13 05:38:34 UTC
Stable for HPPA.
Comment 5 Agostino Sarubbo gentoo-dev 2014-09-13 17:06:42 UTC
amd64 stable
Comment 6 Agostino Sarubbo gentoo-dev 2014-09-13 17:07:28 UTC
x86 stable
Comment 7 Agostino Sarubbo gentoo-dev 2014-09-13 17:35:19 UTC
alpha stable
Comment 8 Agostino Sarubbo gentoo-dev 2014-09-13 17:38:42 UTC
ia64 stable
Comment 9 Agostino Sarubbo gentoo-dev 2014-09-14 07:48:08 UTC
ppc64 stable
Comment 10 Agostino Sarubbo gentoo-dev 2014-09-14 07:51:44 UTC
ppc stable
Comment 11 Agostino Sarubbo gentoo-dev 2014-09-19 10:31:51 UTC
sparc stable
Comment 12 Markus Meier gentoo-dev 2014-09-21 20:12:48 UTC
arm stable, all arches done.
Comment 13 Andreas K. Hüttel archtester gentoo-dev 2014-09-21 21:01:42 UTC
All vulnerable versions removed. Printing out.
Comment 14 Yury German Gentoo Infrastructure gentoo-dev 2014-09-22 03:41:57 UTC
Arches and Maintainer(s), Thank you for your work.

GLSA Vote: No
Comment 15 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2014-11-04 08:11:20 UTC
GLSA vote: no.

Closed as [noglsa].