First published: Sun Jun 22 2014(Updated: )
cups-browsed in cups-filters before 1.0.53 allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a malformed cups-browsed.conf BrowseAllow directive that is interpreted as granting browse access to all IP addresses.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
CUPS Filters | <=1.0.52 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4338 is considered a medium severity vulnerability due to its potential to allow unauthorized access.
To fix CVE-2014-4338, upgrade to cups-filters version 1.0.53 or later.
CVE-2014-4338 affects users of cups-filters versions prior to 1.0.53 on Linux systems.
CVE-2014-4338 is a configuration vulnerability that allows remote attackers to gain unintended access.
Yes, CVE-2014-4338 can be exploited remotely if the cups-browsed.conf file is misconfigured.