Two issues have been found in cups, the Common UNIX Printing System(tm). CVE-2023-4504 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3594-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Thorsten Alteholz September 30, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : cups Version : 2.2.10-6+deb10u9 CVE ID : CVE-2023-4504 CVE-2023-32360 Debian Bug : #1051953 Two issues have been found in cups, the Common UNIX Printing System(tm). CVE-2023-4504 Due to missing boundary checks a heap-based buffer overflow and code execution might be possible by using crafted postscript documents. CVE-2023-32360 Unauthorized users might be allowed to fetch recently printed documents. Since this is a configuration fix, it might be that it does not reach you if you are updating the package. Please double check your /etc/cups/cupds.conf file, whether it limits the access to CUPS-Get-Document with something like the following > > AuthType Default > Require user @OWNER @SYSTEM > Order deny,allow > (The important line is the 'AuthType Default' in this section) For Debian 10 buster, these problems have been fixed in version 2.2.10-6+deb10u9. We recommend that you upgrade your cups packages. For the detailed security status of cups please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/cups Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu LTS USN-4567-2 tackles essential samba vulnerabilities concerning memory corruption and unapproved data exposure.. Debian Security,CUPS Update,Bug Fix,Buffer Overflow,Document Access. . Severity: Critical.LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.