The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4776 http://linux.oracle.com/errata/ELSA-2024-4776.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: cups-2.3.3op2-27.el9_4.x86_64.rpm cups-client-2.3.3op2-27.el9_4.x86_64.rpm cups-devel-2.3.3op2-27.el9_4.i686.rpm cups-devel-2.3.3op2-27.el9_4.x86_64.rpm cups-filesystem-2.3.3op2-27.el9_4.noarch.rpm cups-ipptool-2.3.3op2-27.el9_4.x86_64.rpm cups-libs-2.3.3op2-27.el9_4.i686.rpm cups-libs-2.3.3op2-27.el9_4.x86_64.rpm cups-lpd-2.3.3op2-27.el9_4.x86_64.rpm cups-printerapp-2.3.3op2-27.el9_4.x86_64.rpm aarch64: cups-2.3.3op2-27.el9_4.aarch64.rpm cups-client-2.3.3op2-27.el9_4.aarch64.rpm cups-devel-2.3.3op2-27.el9_4.aarch64.rpm cups-filesystem-2.3.3op2-27.el9_4.noarch.rpm cups-ipptool-2.3.3op2-27.el9_4.aarch64.rpm cups-libs-2.3.3op2-27.el9_4.aarch64.rpm cups-lpd-2.3.3op2-27.el9_4.aarch64.rpm cups-printerapp-2.3.3op2-27.el9_4.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//cups-2.3.3op2-27.el9_4.src.rpm Related CVEs: CVE-2024-35235 Description of changes: [1:2.3.3op2-27] - Revert the cups-libs license identifier to the "legacy" format [1:2.3.3op2-26] - RHEL-40388 cups: Cupsd Listen arbitrary chmod 0140777 - Delete the domain socket file after stopping the cups.socket service - Fix cupsd Listener checks [1:2.3.3op2-25] - CVE-2024-35235 cups: Cupsd Listen arbitrary chmod 0140777 _______________________________________________ El-errata mailing list
New cups packages are available for Slackware 15.0 and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] cups (SSA:2024-163-02) New cups packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/cups-2.4.9-i586-1_slack15.0.txz: Upgraded. This update fixes bugs and a security issue: When starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. For more information, see: https://www.cve.org/CVERecord?id=CVE-2024-35235 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: eb7a13c45409a0db64a5a5c344c2b249 cups-2.4.9-i586-1_slack15.0.txz Slackware x86_64 15.0 package: d270e3ec0741a67116a32bfa9301f4fe cups-2.4.9-x86_64-1_slack15.0.txz Slackware -current package: 433355277a0f061d6a9b7fcb1f9ad5f5 ap/cups-2.4.9-i586-1.txz Slackware x86_64 -current package: 49f32bc3bbcf751650cd28f1d4de4694 ap/cups-2.4.9-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg cups-2.4.9-i586-1_slack15.0.txz Then, restart the cups server: # sh /etc/rc.d/rc.cups restart +-----+ . Recent cup updates for Slackware resolve a significant flaw leading to improper access settings.. SlackwareSecurity,cups Update,Access Control Issue,Cups Package Security. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.