Fix for remote vulnerabilities against OpenPrinting cups-filters. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-01127974ec 2024-09-28 01:26:49.812274 -------------------------------------------------------------------------------- Name : libppd Product : Fedora 40 Version : 2.1~b1 Release : 2.fc40 URL : https://github.com/OpenPrinting/libppd Summary : Library for retro-fitting legacy printer drivers Description : Libppd provides all PPD related function/API which is going to be removed from CUPS 3.X, but are still required for retro-fitting support of legacy printers. The library is meant only for retro-fitting printer applications, any new printer drivers have to be written as native printer application without libppd. -------------------------------------------------------------------------------- Update Information: Fix for remote vulnerabilities against OpenPrinting cups-filters -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 26 2024 Justin M. Forbes - 1:2.1~b1-2 - Fix for CVE-2024-47175 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2314997 - [Major Incident] CVE-2024-47176 cups-browsed: cups-browsed binds on UDP INADDR_ANY:631 trusting any packet from any source [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2314997 [ 2 ] Bug #2315000 - [Major Incident] CVE-2024-47076 libcupsfilters: `cfGetPrinterAttributes` API does not perform sanitization on returned IPP attributes [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2315000 [ 3 ] Bug #2315004 - [Major Incident] CVE-2024-47175 libppd: remote command injection via attacker controlled data in PPD file [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2315004 [ 4 ] Bug #2315005 - [Major Incident] CVE-2024-47177 cups-filters: foomatic-rip incups-filters allows arbitrary command execution via the FoomaticRIPCommandLine PPD parameter [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2315005 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-01127974ec' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fix for remote vulnerabilities against OpenPrinting cups-filters. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-cf6ab63871 2024-09-28 01:19:53.104014 -------------------------------------------------------------------------------- Name : libppd Product : Fedora 39 Version : 2.1~b1 Release : 2.fc39 URL : https://github.com/OpenPrinting/libppd Summary : Library for retro-fitting legacy printer drivers Description : Libppd provides all PPD related function/API which is going to be removed from CUPS 3.X, but are still required for retro-fitting support of legacy printers. The library is meant only for retro-fitting printer applications, any new printer drivers have to be written as native printer application without libppd. -------------------------------------------------------------------------------- Update Information: Fix for remote vulnerabilities against OpenPrinting cups-filters -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 26 2024 Justin M. Forbes - 1:2.1~b1-2 - Fix for CVE-2024-47175 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2314996 - [Major Incident] CVE-2024-47176 cups-browsed: cups-browsed binds on UDP INADDR_ANY:631 trusting any packet from any source [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2314996 [ 2 ] Bug #2314999 - [Major Incident] CVE-2024-47076 libcupsfilters: `cfGetPrinterAttributes` API does not perform sanitization on returned IPP attributes [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2314999 [ 3 ] Bug #2315002 - [Major Incident] CVE-2024-47175 libppd: remote command injection via attacker controlled data in PPD file [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2315002 [ 4 ] Bug #2315003 - [Major Incident] CVE-2024-47177 cups-filters: foomatic-rip incups-filters allows arbitrary command execution via the FoomaticRIPCommandLine PPD parameter [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2315003 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-cf6ab63871' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fix for remove vulnerabilities against OpenPrinting cups-filters. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-3fc82fed09 2024-09-28 00:15:18.613057 -------------------------------------------------------------------------------- Name : libppd Product : Fedora 41 Version : 2.1~b1 Release : 2.fc41 URL : https://github.com/OpenPrinting/libppd Summary : Library for retro-fitting legacy printer drivers Description : Libppd provides all PPD related function/API which is going to be removed from CUPS 3.X, but are still required for retro-fitting support of legacy printers. The library is meant only for retro-fitting printer applications, any new printer drivers have to be written as native printer application without libppd. -------------------------------------------------------------------------------- Update Information: Fix for remove vulnerabilities against OpenPrinting cups-filters -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 26 2024 Justin M. Forbes - 1:2.1~b1-2 - Fix for CVE-2024-47175 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-3fc82fed09' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
libppd could be made to run programs if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-7045-1 September 26, 2024 libppd vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: libppd could be made to run programs if it received specially crafted network traffic. Software Description: - libppd: OpenPrinting libppd Details: Simone Margaritelli discovered that libppd incorrectly sanitized IPP data when creating PPD files. A remote attacker could possibly use this issue to manipulate PPD files and execute arbitrary code when a printer is used. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libppd-utils 2:2.0.0-0ubuntu4.1 libppd2 2:2.0.0-0ubuntu4.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7045-1 CVE-2024-47175 Package Information: https://launchpad.net/ubuntu/+source/libppd/2:2.0.0-0ubuntu4.1 . This report addresses the libxyz vulnerability impacting Debian, which poses a risk of unauthorized access through specially crafted packets.. libppd, network vulnerability, remote code execution, Ubuntu Security Notice. . Severity: Critical. LinuxSecurity.com Team
CVE-2023-4504 libppd: Postscript Parsing Heap Overflow. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-52aa3d1a4f 2023-09-29 00:18:30.089845 -------------------------------------------------------------------------------- Name : libppd Product : Fedora 39 Version : 2.0~rc2 Release : 4.fc39 URL : https://github.com/OpenPrinting/libppd Summary : Library for retro-fitting legacy printer drivers Description : Libppd provides all PPD related function/API which is going to be removed from CUPS 3.X, but are still required for retro-fitting support of legacy printers. The library is meant only for retro-fitting printer applications, any new printer drivers have to be written as native printer application without libppd. -------------------------------------------------------------------------------- Update Information: CVE-2023-4504 libppd: Postscript Parsing Heap Overflow -------------------------------------------------------------------------------- ChangeLog: * Wed Sep 20 2023 Zdenek Dohnal - 1:2.0~rc2-4 - CVE-2023-4504 libppd: Postscript Parsing Heap Overflow -------------------------------------------------------------------------------- References: [ 1 ] Bug #2238509 - CVE-2023-4504 cups, libppd: Postscript Parsing Heap Overflow https://bugzilla.redhat.com/show_bug.cgi?id=2238509 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-52aa3d1a4f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
CVE-2023-4504 libppd: Postscript Parsing Heap Overflow. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-00484b4120 2023-09-26 01:21:18.322480 -------------------------------------------------------------------------------- Name : libppd Product : Fedora 38 Version : 2.0~rc2 Release : 4.fc38 URL : https://github.com/OpenPrinting/libppd Summary : Library for retro-fitting legacy printer drivers Description : Libppd provides all PPD related function/API which is going to be removed from CUPS 3.X, but are still required for retro-fitting support of legacy printers. The library is meant only for retro-fitting printer applications, any new printer drivers have to be written as native printer application without libppd. -------------------------------------------------------------------------------- Update Information: CVE-2023-4504 libppd: Postscript Parsing Heap Overflow -------------------------------------------------------------------------------- ChangeLog: * Wed Sep 20 2023 Zdenek Dohnal - 1:2.0~rc2-4 - CVE-2023-4504 libppd: Postscript Parsing Heap Overflow -------------------------------------------------------------------------------- References: [ 1 ] Bug #2238509 - CVE-2023-4504 cups, libppd: Postscript Parsing Heap Overflow https://bugzilla.redhat.com/show_bug.cgi?id=2238509 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-00484b4120' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
libppd could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-6392-1 September 20, 2023 libppd vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 Summary: libppd could be made to crash or run programs if it opened a specially crafted file. Software Description: - libppd: OpenPrinting libppd Details: It was discovered that libppd incorrectly parsed certain Postscript objects. If a user or automated system were tricked into printing a specially crafted document, a remote attacker could use this issue to cause libppd to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: libppd2 2:2.0~rc1-0ubuntu1.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6392-1 CVE-2023-4504 Package Information: https://launchpad.net/ubuntu/+source/libppd/2:2.0~rc1-0ubuntu1.2 . Libppd in Ubuntu 23.04 has been found to have vulnerabilities that might result in system crashes and allow arbitrary code execution if exploited. libppd Security, Ubuntu Vulnerability, Denial Of Service, Software Update. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.