Bug 13783 - cups new security issues CVE-2014-3537, CVE-2014-5029, and CVE-2014-503[01]
Summary: cups new security issues CVE-2014-3537, CVE-2014-5029, and CVE-2014-503[01]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/606069/
Whiteboard: MGA3TOO MGA3-32-OK MGA4-32-OK advisory
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2014-07-22 16:47 CEST by David Walser
Modified: 2014-08-05 22:24 CEST (History)
3 users (show)

See Also:
Source RPM: cups-1.7.0-7.1.mga4.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2014-07-22 16:47:24 CEST
Fedora has issued an advisory on July 16:
https://lists.fedoraproject.org/pipermail/package-announce/2014-July/135528.html

The issue is fixed upstream in 1.7.4 (already in Cauldron).

Patched packages uploaded for Mageia 3 and Mageia 4.

Advisory:
========================

Updated cups packages fix security vulnerability:

In CUPS before 1.7.4, a local user with privileges of group=lp can write
symbolic links in the rss directory and use that to gain '@SYSTEM' group
privilege with cupsd (CVE-2014-3537).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3537
https://lists.fedoraproject.org/pipermail/package-announce/2014-July/135528.html
========================

Updated packages in core/updates_testing:
========================
cups-1.5.4-9.3.mga3
cups-common-1.5.4-9.3.mga3
libcups2-1.5.4-9.3.mga3
libcups2-devel-1.5.4-9.3.mga3
cups-serial-1.5.4-9.3.mga3
php-cups-1.5.4-9.3.mga3
cups-1.7.0-7.2.mga4
cups-common-1.7.0-7.2.mga4
libcups2-devel-1.7.0-7.2.mga4
libcups2-1.7.0-7.2.mga4
cups-filesystem-1.7.0-7.2.mga4

from SRPMS:
cups-1.5.4-9.3.mga3.src.rpm
cups-1.7.0-7.2.mga4.src.rpm

Reproducible: 

Steps to Reproduce:
David Walser 2014-07-22 16:47:34 CEST

Whiteboard: (none) => MGA3TOO

Comment 1 David Walser 2014-07-30 20:45:37 CEST
CVEs were allocated on July 22 for more security issues fixed upstream:
http://openwall.com/lists/oss-security/2014/07/22/13

LWN reference for CVE-2014-5029 and CVE-2014-503[01]:
http://lwn.net/Vulnerabilities/606882/

Debian has issued an advisory for this on July 27:
https://www.debian.org/security/2014/dsa-2990

Patched packages uploaded for Mageia 3, Mageia 4, and Cauldron.

Advisory:
========================

Updated cups packages fix security vulnerabilities:

In CUPS before 1.7.4, a local user with privileges of group=lp can write
symbolic links in the rss directory and use that to gain '@SYSTEM' group
privilege with cupsd (CVE-2014-3537).

It was discovered that the web interface in CUPS incorrectly validated
permissions on rss files and directory index files. A local attacker could
possibly use this issue to bypass file permissions and read arbitrary files,
possibly leading to a privilege escalation (CVE-2014-5029, CVE-2014-5030,
CVE-2014-5031).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3537
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5029
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5030
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5031
https://lists.fedoraproject.org/pipermail/package-announce/2014-July/135528.html
https://www.debian.org/security/2014/dsa-2990
========================

Updated packages in core/updates_testing:
========================
cups-1.5.4-9.4.mga3
cups-common-1.5.4-9.4.mga3
libcups2-1.5.4-9.4.mga3
libcups2-devel-1.5.4-9.4.mga3
cups-serial-1.5.4-9.4.mga3
php-cups-1.5.4-9.4.mga3
cups-1.7.0-7.3.mga4
cups-common-1.7.0-7.3.mga4
libcups2-devel-1.7.0-7.3.mga4
libcups2-1.7.0-7.3.mga4
cups-filesystem-1.7.0-7.3.mga4

from SRPMS:
cups-1.5.4-9.4.mga3.src.rpm
cups-1.7.0-7.3.mga4.src.rpm

Summary: cups new security issue CVE-2014-3537 => cups new security issues CVE-2014-3537, CVE-2014-5029, and CVE-2014-503[01]

Comment 2 David Walser 2014-08-01 15:44:14 CEST
Validating this.  See the discussion in the QA meeting:
http://meetbot.mageia.org/mageia-qa/2014/mageia-qa.2014-07-31-19.02.log.html#l-30

Note that Debian and Fedora have both already built updates with these patches, which come from upstream.  Also, CUPS 1.7.5 has been released containing these same fixes.

The advisory still needs to be uploaded.

Please push this to core/updates for Mageia 3 and Mageia 4.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 3 Rémi Verschelde 2014-08-01 23:34:51 CEST
Advisory uploaded.

CC: (none) => remi
Whiteboard: MGA3TOO => MGA3TOO advisory

Comment 4 Rémi Verschelde 2014-08-04 21:50:37 CEST
Installs fine on Mageia 4 32bit.

Whiteboard: MGA3TOO advisory => MGA3TOO MGA4-32-OK advisory

Comment 5 Rémi Verschelde 2014-08-05 19:58:21 CEST
Made sure it installs in Mageia 3 32bit.

Whiteboard: MGA3TOO MGA4-32-OK advisory => MGA3TOO MGA3-32-OK MGA4-32-OK advisory

Comment 6 Colin Guthrie 2014-08-05 22:24:55 CEST
Update pushed.

http://advisories.mageia.org/MGASA-2014-0313.html

Status: NEW => RESOLVED
CC: (none) => mageia
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.