Fix for remote vulnerabilities against OpenPrinting cups-filters. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-cf6ab63871 2024-09-28 01:19:53.104014 -------------------------------------------------------------------------------- Name : cups-browsed Product : Fedora 39 Version : 2.0.1 Release : 3.fc39 URL : https://github.com/OpenPrinting/cups-browsed Summary : Daemon for local auto-installation of remote printers Description : cups-browsed is a helper daemon, which automatically installs printers locally, provides load balancing and clustering of print queues. The daemon installs the printers based on found mDNS records and CUPS broadcast, or by polling a remote print server. -------------------------------------------------------------------------------- Update Information: Fix for remote vulnerabilities against OpenPrinting cups-filters -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 26 2024 Justin M. Forbes - 1:2.0.1-2 - Fix for CVE-2024-47176 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2314996 - [Major Incident] CVE-2024-47176 cups-browsed: cups-browsed binds on UDP INADDR_ANY:631 trusting any packet from any source [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2314996 [ 2 ] Bug #2314999 - [Major Incident] CVE-2024-47076 libcupsfilters: `cfGetPrinterAttributes` API does not perform sanitization on returned IPP attributes [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2314999 [ 3 ] Bug #2315002 - [Major Incident] CVE-2024-47175 libppd: remote command injection via attacker controlled data in PPD file [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2315002 [ 4 ] Bug #2315003 - [Major Incident] CVE-2024-47177 cups-filters: foomatic-rip in cups-filters allows arbitrary command execution viathe FoomaticRIPCommandLine PPD parameter [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2315003 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-cf6ab63871' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.