CUPS Print Service Privilege Escalation Vulnerability (CVE-2015-1158)

  Severity: CRITICAL
  Advisory Date: JUL 21, 2015

  DESCRIPTION

A string reference count bug was found in cupsd, causing premature freeing of string objects. An attacker could submit a malicious print job that exploits this flaw to dismantle ACLs protecting privileged operations, allowing a replacement configuration file to be uploaded, which in turn allowed the attacker to run arbitrary code on the CUPS server.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1006814

Featured Stories