Debian-LTS alert DLA-159-1 (cups)
From: | Ben Hutchings <benh@debian.org> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 159-1] cups security update | |
Date: | Fri, 27 Feb 2015 13:03:07 +0000 | |
Message-ID: | <1425042187.28544.37.camel@debian.org> |
Package : cups Version : 1.4.4-7+squeeze7 CVE ID : CVE-2014-9679 Debian Bug : #778387 Peter De Wachter discovered that CUPS, the Common UNIX Printing System, did not correctly parse compressed raster files. By submitting a specially crafted raster file, a remote attacker could use this vulnerability to trigger a buffer overflow. For the oldstable distribution (squeeze), this problem has been fixed in version 1.4.4-7+squeeze7. For the stable distribution (wheezy), this problem has been fixed in version 1.5.3-5+deb7u5. We recommend that you upgrade your cups packages. -- Ben Hutchings - Debian developer, kernel team member