This update fixes several security issues: CVE-2009-0163, CVE-2009-0164, CVE-2009-0146, CVE-2009-0147, and CVE-2009-0166. PDF files are now converted to PostScript using the poppler package's "pdftops" program. NOTE: If your CUPS server is accessed using a hostname or hostnames not known to the server itself you must add "ServerAlias hostname" to cupsd.conf for each such name. The special line "ServerAlias *" disables checking (but this allows DNS rebinding attacks).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-3753 2009-04-21 23:54:41 -------------------------------------------------------------------------------- Name : cups Product : Fedora 9 Version : 1.3.10 Release : 1.fc9 URL : http://www.cups.org/ Summary : Common Unix Printing System Description : The Common UNIX Printing System provides a portable printing layer for UNIX® operating systems. It has been developed by Easy Software Products to promote a standard printing solution for all UNIX vendors and users. CUPS provides the System V and Berkeley command-line interfaces. -------------------------------------------------------------------------------- Update Information: This update fixes several security issues: CVE-2009-0163, CVE-2009-0164, CVE-2009-0146, CVE-2009-0147, and CVE-2009-0166. PDF files are now converted to PostScript using the poppler package's "pdftops" program. NOTE: If your CUPS server is accessed using a hostname or hostnames not known to the server itself you must add "ServerAlias hostname" to cupsd.conf for each such name. The special line "ServerAlias *" disables checking (but this allows DNS rebinding attacks). -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 21 2009 Tim Waugh 1:1.3.10-1 - 1.3.10. No longer need ext, includeifexists, str2988, CVE-2008-5183, CVE-2008-5286, str3077, str3078, str3059, str3055 patches. - Requires poppler-utils. - NOTE:If your CUPS server is accessed using a hostname or hostnames not known to the server itself you must add "ServerAlias hostname" for each such name. The special line "ServerAlias *" disables checking (but this allows DNS rebinding attacks). * Fri Apr 17 2009 Tim Waugh - Fixed getnameddest patch (bug #481481, STR #3082). * Wed Jan 28 2009 Tim Waugh 1:1.3.9-4 - Always supply document-name when printing a file (STR #3055). - Load MIME type rules correctly (bug #426089, STR #3059). - Fixed quotas (STR #3077, STR #3078). - Removed all patch fuzz. * Tue Dec 9 2008 Tim Waugh 1:1.3.9-3 - Removed dnssd backend as it was causing problems (bug #475230). - Attempt to unbreak the fix for STR #2831 (bug #474742). * Wed Dec 3 2008 Tim Waugh 1:1.3.9-2 - Applied patch to fix STR #2974 (bug #473905, CVE-2008-5286, CVE-2008-1722). - Applied patch to fix RSS subscription limiting (bug #473901, CVE-2008-5183). - Fixed cups-polld again for res_init (STR #3023, bug #354071). - Added patch to avoid polling busy loop (STR #2988). - Fixed textonly filter to send FF correctly. * Fri Oct 10 2008 Tim Waugh 1:1.3.9-1 - 1.3.9, including fixes for CVE-2008-3639 / STR #2918, CVE-2008-3640 / STR #2919 and CVE-2008-3641 / STR #2911 (bug #466419). - No longer need str2892 or res_init patches. * Wed Sep 10 2008 Tim Waugh - Backported patch for FatalErrors configuration directive (bug #314941, STR #2536). * Wed Sep 3 2008 Tim Waugh - The dnssd backend uses avahi-browse so require it (bug #458565). - cups-polld: reinit the resolver if we haven't yet resolved the hostname (bug #354071). * Tue Aug 5 2008 Tim Waugh 1:1.3.8-2 - Mark template files config(noreplace) for site-local modifications (bug #441719). * Sun Aug 3 2008 Tim Waugh 1:1.3.8-1 - 1.3.8. - Applied patch to fix STR #2892 (bug #453610). - Removed autoconf requirement by applying autoconf-generated changes to patches that caused them. Affected patches: cups-lspp. - CVE-2008-1373 patch is no longer needed (applied upstream). - Mark HTML files andtemplates config(noreplace) for site-local modifications (bug #441719). - The cups-devel package requires zlib-devel (bug #455192). * Tue Jul 1 2008 Tim Waugh 1:1.3.7-8 - Fixed bug #447200 again. * Tue Jun 17 2008 Tim Waugh - Don't overwrite the upstream snmp.conf file. * Tue Jun 17 2008 Tim Waugh 1:1.3.7-7 - Backported cupsGetNamedDest from 1.4 (bug #428086). - Fixed bug #447200 again. * Tue Jun 3 2008 Tim Waugh 1:1.3.7-6 - Applied patch to fix STR #2750 (IPP authentication). * Fri May 30 2008 Tim Waugh 1:1.3.7-5 - Better fix for cupsdTimeoutJob LSPP configuration suggested by Matt Anderson (bug #447200). * Thu May 29 2008 Tim Waugh 1:1.3.7-4 - Fix last fix (bug #447200). * Wed May 28 2008 Tim Waugh 1:1.3.7-3 - If cupsdTimeoutJob is called when the originating connection is still known, pass that to the function so that copy_banner can get at it if necessary (bug #447200). * Fri May 9 2008 Tim Waugh 1:1.3.7-2 - Applied patch to fix CVE-2008-1722 (integer overflow in image filter, bug #441692, STR #2790). * Thu Apr 3 2008 Tim Waugh - Main package requires exactly-matching libs package. -------------------------------------------------------------------------------- References: [ 1 ] Bug #490597 - CVE-2009-0164 cups: insufficient checking of the HTTP Host: header https://bugzilla.redhat.com/show_bug.cgi?id=490597 [ 2 ] Bug #490596 - CVE-2009-0163 cups: Integer overflow in the TIFF image filter https://bugzilla.redhat.com/show_bug.cgi?id=490596 [ 3 ] Bug #490612 - CVE-2009-0146 xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) https://bugzilla.redhat.com/show_bug.cgi?id=490612 [ 4 ] Bug #490614 - CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder https://bugzilla.redhat.com/show_bug.cgi?id=490614 [ 5 ] Bug #490625 - CVE-2009-0166 xpdf: Freeing of potentially uninitialized memory in JBIG2 decoder https://bugzilla.redhat.com/show_bug.cgi?id=490625 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update cups' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
Updated CUPS packages that fix a security issue are now available for Red Hat Enterprise Linux 3. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: cups security update Advisory ID: RHSA-2005:571-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:571.html Issue date: 2005-07-14 Updated on: 2005-07-14 Product: Red Hat Enterprise Linux CVE Names: CAN-2004-2154 - ---------------------------------------------------------------------1. Summary: Updated CUPS packages that fix a security issue are now available for Red Hat Enterprise Linux 3. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: The Common UNIX Printing System (CUPS) provides a portable printing layer for UNIX(R) operating systems. When processing a request, the CUPS scheduler would use case-sensitive matching on the queue name to decide which authorization policy should be used. However, queue names are not case-sensitive. An unauthorized user could print to a password-protected queue without needing a password. The Common Vulnerabilities and Exposures project has assigned the name CAN-2005-2154 to this issue. Please note that the version of CUPS included in Red Hat Enterprise Linux 4 is not vulnerable to this issue. All users of CUPS should upgrade to these erratum packages which contain a backported patch to correct this issue. 4. Solution: Before applying this update, make sure that allpreviously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 162405 - CAN-2004-2154 directive is case-sensitive in cupsd.conf but should not 6. RPMs required: Red Hat Enterprise Linux AS version 3: SRPMS: 81c72be8ece7d629a9a73ffa32916c41 cups-1.1.17-13.3.29.src.rpm i386: 36bdfb6c6aa5eb58d5fe41b457ac7361 cups-1.1.17-13.3.29.i386.rpm 72307b7ee7bba211a5546a28362ac2a6 cups-devel-1.1.17-13.3.29.i386.rpm 5dc46b9df27b30286b6604c6a1e6ee98 cups-libs-1.1.17-13.3.29.i386.rpm ia64: 36d374d2e1abacc34ce965750541626b cups-1.1.17-13.3.29.ia64.rpm 7f3441b9e9879be1087bcd0607b1ab66 cups-devel-1.1.17-13.3.29.ia64.rpm 5dc46b9df27b30286b6604c6a1e6ee98 cups-libs-1.1.17-13.3.29.i386.rpm a96ac4679c8b522d5433f23fade03f07 cups-libs-1.1.17-13.3.29.ia64.rpm ppc: 86f8571af07d8d5fa479ed729a13af37 cups-1.1.17-13.3.29.ppc.rpm ff62e1f6ae117e1db87a4299a4bd33a9 cups-devel-1.1.17-13.3.29.ppc.rpm 6e334775b2dbb8c09c25e011cb69cba4 cups-libs-1.1.17-13.3.29.ppc.rpm 9f23a140336a37a76bf6a9dbcbcdb9ff cups-libs-1.1.17-13.3.29.ppc64.rpm s390: 54d08a23a20b825b5c0c1e59ea0fe54b cups-1.1.17-13.3.29.s390.rpm eb62a6ea4f287a6eab9a0157f909e9e4 cups-devel-1.1.17-13.3.29.s390.rpm e067385a2f2e9ab235bd9f98943626c7 cups-libs-1.1.17-13.3.29.s390.rpm s390x: d400e53066c2c831ae85155c9b8b0de0 cups-1.1.17-13.3.29.s390x.rpm e3c00601315da00de3b8980a2c93aec8 cups-devel-1.1.17-13.3.29.s390x.rpm e067385a2f2e9ab235bd9f98943626c7 cups-libs-1.1.17-13.3.29.s390.rpm f6bb5b5be02c4acd32561a7a857c7eae cups-libs-1.1.17-13.3.29.s390x.rpm x86_64: a692e1999e3ee1a95f3053d894675100 cups-1.1.17-13.3.29.x86_64.rpm 7f56302afb665afafcf61577a31bb1d6 cups-devel-1.1.17-13.3.29.x86_64.rpm 5dc46b9df27b30286b6604c6a1e6ee98 cups-libs-1.1.17-13.3.29.i386.rpm 56379591a637d0085b0838e0d97f0111 cups-libs-1.1.17-13.3.29.x86_64.rpm Red Hat Desktop version 3: SRPMS: 81c72be8ece7d629a9a73ffa32916c41 cups-1.1.17-13.3.29.src.rpm i386: 36bdfb6c6aa5eb58d5fe41b457ac7361 cups-1.1.17-13.3.29.i386.rpm 72307b7ee7bba211a5546a28362ac2a6 cups-devel-1.1.17-13.3.29.i386.rpm 5dc46b9df27b30286b6604c6a1e6ee98 cups-libs-1.1.17-13.3.29.i386.rpm x86_64: a692e1999e3ee1a95f3053d894675100 cups-1.1.17-13.3.29.x86_64.rpm 7f56302afb665afafcf61577a31bb1d6 cups-devel-1.1.17-13.3.29.x86_64.rpm 5dc46b9df27b30286b6604c6a1e6ee98 cups-libs-1.1.17-13.3.29.i386.rpm 56379591a637d0085b0838e0d97f0111 cups-libs-1.1.17-13.3.29.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: 81c72be8ece7d629a9a73ffa32916c41 cups-1.1.17-13.3.29.src.rpm i386: 36bdfb6c6aa5eb58d5fe41b457ac7361 cups-1.1.17-13.3.29.i386.rpm 72307b7ee7bba211a5546a28362ac2a6 cups-devel-1.1.17-13.3.29.i386.rpm 5dc46b9df27b30286b6604c6a1e6ee98 cups-libs-1.1.17-13.3.29.i386.rpm ia64: 36d374d2e1abacc34ce965750541626b cups-1.1.17-13.3.29.ia64.rpm 7f3441b9e9879be1087bcd0607b1ab66 cups-devel-1.1.17-13.3.29.ia64.rpm 5dc46b9df27b30286b6604c6a1e6ee98 cups-libs-1.1.17-13.3.29.i386.rpm a96ac4679c8b522d5433f23fade03f07 cups-libs-1.1.17-13.3.29.ia64.rpm x86_64: a692e1999e3ee1a95f3053d894675100 cups-1.1.17-13.3.29.x86_64.rpm 7f56302afb665afafcf61577a31bb1d6 cups-devel-1.1.17-13.3.29.x86_64.rpm 5dc46b9df27b30286b6604c6a1e6ee98 cups-libs-1.1.17-13.3.29.i386.rpm 56379591a637d0085b0838e0d97f0111 cups-libs-1.1.17-13.3.29.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: 81c72be8ece7d629a9a73ffa32916c41 cups-1.1.17-13.3.29.src.rpm i386: 36bdfb6c6aa5eb58d5fe41b457ac7361 cups-1.1.17-13.3.29.i386.rpm 72307b7ee7bba211a5546a28362ac2a6 cups-devel-1.1.17-13.3.29.i386.rpm 5dc46b9df27b30286b6604c6a1e6ee98 cups-libs-1.1.17-13.3.29.i386.rpm ia64: 36d374d2e1abacc34ce965750541626b cups-1.1.17-13.3.29.ia64.rpm 7f3441b9e9879be1087bcd0607b1ab66 cups-devel-1.1.17-13.3.29.ia64.rpm 5dc46b9df27b30286b6604c6a1e6ee98 cups-libs-1.1.17-13.3.29.i386.rpm a96ac4679c8b522d5433f23fade03f07 cups-libs-1.1.17-13.3.29.ia64.rpm x86_64: a692e1999e3ee1a95f3053d894675100 cups-1.1.17-13.3.29.x86_64.rpm 7f56302afb665afafcf61577a31bb1d6 cups-devel-1.1.17-13.3.29.x86_64.rpm 5dc46b9df27b30286b6604c6a1e6ee98 cups-libs-1.1.17-13.3.29.i386.rpm 56379591a637d0085b0838e0d97f0111 cups-libs-1.1.17-13.3.29.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CAN-2004-2154 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2005 Red Hat, Inc. . Important security patch for Red Hat resolves exploitation risks related to unauthorized entry into secured message queues, fortifying overall system integrity.. cups Update, Red Hat Advisory, Security Patch, Moderate Impact, Printing Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.