LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
What is the most important Linux security technology?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
All About Linux
DanWalsh LiveJournal
Securitydistro
Latest Newsletters
Linux Advisory Watch: November 28th, 2014
Linux Advisory Watch: November 21st, 2014
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Fedora 9 Update: cups-1.3.9-2.fc9 Print E-mail
User Rating:      How can I rate this item?
Posted by Benjamin D. Thomas   
Fedora Security update to fix CVE-2008-5183. Also fixed in this update are a bug that caused cups-polld to fail to resolve hostnames, a bug that could cause libcups to get stuck in a loop, and incorrect form-feed handling in the textonly filter.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-10917
None
--------------------------------------------------------------------------------

Name        : cups
Product     : Fedora 9
Version     : 1.3.9
Release     : 2.fc9
URL         : http://www.cups.org/
Summary     : Common Unix Printing System
Description :
The Common UNIX Printing System provides a portable printing layer for
UNIX® operating systems. It has been developed by Easy Software Products
to promote a standard printing solution for all UNIX vendors and users.
CUPS provides the System V and Berkeley command-line interfaces.

--------------------------------------------------------------------------------
Update Information:

Security update to fix CVE-2008-5183.    Also fixed in this update are a bug
that caused cups-polld to fail to resolve hostnames, a bug that could cause
libcups to get stuck in a loop, and incorrect form-feed handling in the textonly
filter.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Dec  3 2008 Tim Waugh  1:1.3.9-2
- Applied patch to fix STR #2974 (bug #473905, CVE-2008-5286,
  CVE-2008-1722).
- Applied patch to fix RSS subscription limiting (bug #473901,
  CVE-2008-5183).
- Fixed cups-polld again for res_init (STR #3023, bug #354071).
- Added patch to avoid polling busy loop (STR #2988).
- Fixed textonly filter to send FF correctly.
* Fri Oct 10 2008 Tim Waugh  1:1.3.9-1
- 1.3.9, including fixes for CVE-2008-3639 / STR #2918,
  CVE-2008-3640 / STR #2919 and CVE-2008-3641 / STR #2911
  (bug #466419).
- No longer need str2892 or res_init patches.
* Wed Sep 10 2008 Tim Waugh 
- Backported patch for FatalErrors configuration directive
  (bug #314941, STR #2536).
* Wed Sep  3 2008 Tim Waugh 
- The dnssd backend uses avahi-browse so require it (bug #458565).
- cups-polld: reinit the resolver if we haven't yet resolved the
  hostname (bug #354071).
* Tue Aug  5 2008 Tim Waugh  1:1.3.8-2
- Mark template files config(noreplace) for site-local modifications
  (bug #441719).
* Sun Aug  3 2008 Tim Waugh  1:1.3.8-1
- 1.3.8.
- Applied patch to fix STR #2892 (bug #453610).
- Removed autoconf requirement by applying autoconf-generated changes
  to patches that caused them.  Affected patches: cups-lspp.
- CVE-2008-1373 patch is no longer needed (applied upstream).
- Mark HTML files and templates config(noreplace) for site-local
  modifications (bug #441719).
- The cups-devel package requires zlib-devel (bug #455192).
* Tue Jul  1 2008 Tim Waugh  1:1.3.7-8
- Fixed bug #447200 again.
* Tue Jun 17 2008 Tim Waugh 
- Don't overwrite the upstream snmp.conf file.
* Tue Jun 17 2008 Tim Waugh  1:1.3.7-7
- Backported cupsGetNamedDest from 1.4 (bug #428086).
- Fixed bug #447200 again.
* Tue Jun  3 2008 Tim Waugh  1:1.3.7-6
- Applied patch to fix STR #2750 (IPP authentication).
* Fri May 30 2008 Tim Waugh  1:1.3.7-5
- Better fix for cupsdTimeoutJob LSPP configuration suggested by
  Matt Anderson (bug #447200).
* Thu May 29 2008 Tim Waugh  1:1.3.7-4
- Fix last fix (bug #447200).
* Wed May 28 2008 Tim Waugh  1:1.3.7-3
- If cupsdTimeoutJob is called when the originating connection is still
  known, pass that to the function so that copy_banner can get at it if
  necessary (bug #447200).
* Fri May  9 2008 Tim Waugh  1:1.3.7-2
- Applied patch to fix CVE-2008-1722 (integer overflow in image filter,
  bug #441692, STR #2790).
* Thu Apr  3 2008 Tim Waugh 
- Main package requires exactly-matching libs package.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #473901 - CVE-2008-5183 cups: DoS (daemon crash) by adding a large number of RSS subscriptions
        https://bugzilla.redhat.com/show_bug.cgi?id=473901
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update cups' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------

_______________________________________________
Fedora-package-announce mailing list
Fedora-package-announce@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-package-announce
 
< Prev   Next >
    
Partner

 

Latest Features
Peter Smith Releases Linux Network Security Online
Securing a Linux Web Server
Password guessing with Medusa 2.0
Password guessing as an attack vector
Squid and Digest Authentication
Squid and Basic Authentication
Demystifying the Chinese Hacking Industry: Earning 6 Million a Night
Free Online security course (LearnSIA) - A Call for Help
What You Need to Know About Linux Rootkits
Review: A Practical Guide to Fedora and Red Hat Enterprise Linux - Fifth Edition
Yesterday's Edition
Partner Sponsor

Community | HOWTOs | Blogs | Features | Book Reviews | Networking
 Security Projects |  Latest News |  Newsletters |  SELinux |  Privacy |  Home
 Hardening |   About Us |   Advertise |   Legal Notice |   RSS |   Guardian Digital
(c)Copyright 2014 Guardian Digital, Inc. All rights reserved.