| From: |
| opensuse-security@opensuse.org |
| To: |
| opensuse-updates@opensuse.org |
| Subject: |
| openSUSE-SU-2010:1018-1 (important): cups: security update |
| Date: |
| Fri, 3 Dec 2010 20:08:14 +0100 (CET) |
| Message-ID: |
| <20101203190814.1B202BE65@oldboy.suse.de> |
| Archive-link: |
| Article, Thread
|
openSUSE Security Update: cups: security update
______________________________________________________________________________
Announcement ID: openSUSE-SU-2010:1018-1
Rating: important
References: #649256
Cross-References: CVE-2010-0542 CVE-2010-1748 CVE-2010-2941
Affected Products:
openSUSE 11.3
openSUSE 11.2
openSUSE 11.1
______________________________________________________________________________
An update that fixes three vulnerabilities is now available.
Description:
This updates fix several bugs, but only the security fixes
are listed here:
- CVE-2010-2941: CVSS v2 Base Score: 3.3
(AV:A/AC:L/Au:N/C:N/I:N/A:P): CWE-399 Special IPP
requests allow to crashcupsd remotely.
- CVE-2010-0542: CVSS v2 Base Score: 6.8
(AV:N/AC:M/Au:N/C:P/I:P/A:P): CWE-264 A NULL pointer
dereference exists in the _WriteProlog() function of the
texttops image filter.
- CVE-2010-1748: CVSS v2 Base Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N): CWE-119 An attacker with
access to the web-interface may be able to read some
bytes of uninitialized memory.
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.3:
zypper in -t patch cups-3574
- openSUSE 11.2:
zypper in -t patch cups-3574
- openSUSE 11.1:
zypper in -t patch cups-3574
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 11.3 (i586 x86_64):
cups-1.4.4-3.3.1
cups-client-1.4.4-3.3.1
cups-ddk-1.4.4-3.3.1
cups-devel-1.4.4-3.3.1
cups-libs-1.4.4-3.3.1
- openSUSE 11.3 (x86_64):
cups-libs-32bit-1.4.4-3.3.1
- openSUSE 11.2 (i586 x86_64):
cups-1.3.11-4.7.1
cups-client-1.3.11-4.7.1
cups-devel-1.3.11-4.7.1
cups-libs-1.3.11-4.7.1
- openSUSE 11.2 (x86_64):
cups-libs-32bit-1.3.11-4.7.1
- openSUSE 11.1 (i586 ppc x86_64):
cups-1.3.9-7.10.1
cups-client-1.3.9-7.10.1
cups-devel-1.3.9-7.10.1
cups-libs-1.3.9-7.10.1
- openSUSE 11.1 (x86_64):
cups-libs-32bit-1.3.9-7.10.1
- openSUSE 11.1 (ppc):
cups-libs-64bit-1.3.9-7.10.1
References:
http://support.novell.com/security/cve/CVE-2010-0542.html
http://support.novell.com/security/cve/CVE-2010-1748.html
http://support.novell.com/security/cve/CVE-2010-2941.html
https://bugzilla.novell.com/649256
(
Log in to post comments)