Bug 883536 (CVE-2014-4338) - VUL-0: CVE-2014-4338: cups-filters: unsupported BrowseAllow value lets cups-browsed accept from all hosts
Summary: VUL-0: CVE-2014-4338: cups-filters: unsupported BrowseAllow value lets cups-b...
Status: RESOLVED DUPLICATE of bug 871327
Alias: CVE-2014-4338
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Johannes Meixner
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/99940/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-06-20 10:56 UTC by Johannes Segitz
Modified: 2014-07-30 14:00 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-06-20 10:56:23 UTC
rh#1091568

cups-browsed: SECURITY FIX: Fix on usage of the "BrowseAllow" directive in cups-browsed.conf. Before, if the argument of a "BrowseAllow" directive is not understood it is treated as the directive not having been there, allowing any host if this was the only "BrowseAllow" directive. Now we treat this as a directive which no host can fulfill, not allowing any host if it was the only one. No "BrowseAllow" directive means access for all, as before.


Issue was discussed in bnc#871327 but SLE12 is not fixed.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1091568
http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7195
https://bugs.linuxfoundation.org/show_bug.cgi?id=1204
Comment 1 Swamp Workflow Management 2014-06-20 22:00:22 UTC
bugbot adjusting priority
Comment 2 Johannes Meixner 2014-06-23 08:28:38 UTC
It is fixed everywhere, for openSUSE:Factory, for OBS "Printing",
and for SLE12.

See bnc#883543 for details or see the cups-filters.changes files
for openSUSE:Factory, for OBS "Printing", and for SLE12.

FYI:
At the time when we at SUSE had already fixed it there was not yet
CVE-2014-4338 assigned and therefore for example a dumb automated serach
for this CVE-2014-4338 cannot find it in cups-filters.changes.
Comment 3 Johannes Meixner 2014-06-23 09:20:20 UTC

*** This bug has been marked as a duplicate of bug 871327 ***
Comment 5 Bernhard Wiedemann 2014-07-30 14:00:29 UTC
This is an autogenerated message for OBS integration:
This bug (883536) was mentioned in
https://build.opensuse.org/request/show/243029 Factory / cups-filters