Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 27 FEDORA-2018-f2e1c09437 Critical: Cups-Filters Stack Exhaustion

fedora
Calendar Grey April 30, 2018
Dist Fedora Esm H88
Fedora's package of CUPS filters has been updated to mitigate vulnerabilities, notably those related to potential stack overflow and unending loops.
Rebase to qpdf-7.1.1 because of security fixes for CVE-2018-9918, CVE-2017-11627, CVE-2017-12595.

Summary

Contains backends, filters, and other software that was

once part of the core CUPS distribution but is no longer maintained by

Apple Inc. In addition it contains additional filters developed

independently of Apple, especially filters for the PDF-centric printing

workflow introduced by OpenPrinting.

Rebase to qpdf-7.1.1 because of security fixes for CVE-2018-9918,

CVE-2017-11627, CVE-2017-12595.

* Wed Apr 18 2018 Zdenek Dohnal - 1.16.1-5

- rebuilt with qpdf-7.1.1

* Tue Jan 2 2018 Zdenek Dohnal - 1.16.1-4

- 1529680 - set CreateIPPPrintQueues to ALL and LocalRemoteCUPSQueueNaming to RemoteName

* Mon Nov 20 2017 Zdenek Dohnal - 1.16.1-3

- fixing patch for upstream issue 1413

[ 1 ] Bug #1566756 - CVE-2018-9918 qpdf: stack exhaustion in QPDFObjectHandle and QPDF_Dictionary classes in libqpdf.a

https://bugzilla.redhat.com/show_bug.cgi?id=1566756

[ 2 ] Bug #1475517 - CVE-2017-11627 qpdf: Infinite loop in PointerHolder function in PointerHolder.hh

https://bugzilla.redhat.com/show_bug.cgi?id=1475517

[ 3 ] Bug #1485847 - CVE-2017-12595 qpdf: Stack overflow when processing deeply nested arrays and dictionaries

https://bugzilla.redhat.com/show_bug.cgi?id=1485847

su -c 'dnf upgrade --advisory FEDORA-2018-f2e1c09437' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 1.16.1
Release: 5.fc27
Summary: OpenPrinting CUPS filters and backends

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here