You are here
Home > Preporuke > Sigurnosni propust programskog paketa cups-filters

Sigurnosni propust programskog paketa cups-filters

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2015-3036
2015-03-04 07:08:08
——————————————————————————–

Name : cups-filters
Product : Fedora 21
Version : 1.0.66
Release : 1.fc21
URL : http://www.linuxfoundation.org/collaborate/workgroups/openprinting/cups-filters
Summary : OpenPrinting CUPS filters and backends
Description :
Contains backends, filters, and other software that was
once part of the core CUPS distribution but is no longer maintained by
Apple Inc. In addition it contains additional filters developed
independently of Apple, especially filters for the PDF-centric printing
workflow introduced by OpenPrinting.

——————————————————————————–
Update Information:

New upstream bug-fix release which fixes a security flaw in cups-browsed.
——————————————————————————–
ChangeLog:

* Mon Mar 2 2015 Jiri Popelka <jpopelka@redhat.com> – 1.0.66-1
– 1.0.66
* Mon Feb 16 2015 Jiri Popelka <jpopelka@redhat.com> – 1.0.65-1
– 1.0.65
* Fri Oct 10 2014 Jiri Popelka <jpopelka@redhat.com> – 1.0.61-1
– 1.0.61
* Tue Oct 7 2014 Jiri Popelka <jpopelka@redhat.com> – 1.0.60-1
– 1.0.60
* Sun Sep 28 2014 Jiri Popelka <jpopelka@redhat.com> – 1.0.59-1
– 1.0.59
——————————————————————————–
References:

[ 1 ] Bug #1199130 – CVE-2015-2265 cups-filters: remote command execution in remove_bad_chars() (incomplete fix for CVE-2014-2707)
https://bugzilla.redhat.com/show_bug.cgi?id=1199130
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update cups-filters’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-3003
2015-03-04 07:06:53
——————————————————————————–

Name : cups-filters
Product : Fedora 20
Version : 1.0.53
Release : 6.fc20
URL : http://www.linuxfoundation.org/collaborate/workgroups/openprinting/cups-filters
Summary : OpenPrinting CUPS filters and backends
Description :
Contains backends, filters, and other software that was
once part of the core CUPS distribution but is no longer maintained by
Apple Inc. In addition it contains additional filters developed
independently of Apple, especially filters for the PDF-centric printing
workflow introduced by OpenPrinting.

——————————————————————————–
Update Information:

This fixes a security flaw in cups-browsed.
——————————————————————————–
ChangeLog:

* Mon Mar 2 2015 Jiri Popelka <jpopelka@redhat.com> – 1.0.53-6
cups-browsed: Fixed a security bug in the remove_bad_chars() failing to
reliably filter out illegal characters. (upstream #1265)
* Fri Jun 13 2014 Tim Waugh <twaugh@redhat.com> – 1.0.53-5
– Really fix execmem issue (bug #1079534).
* Wed Jun 11 2014 Tim Waugh <twaugh@redhat.com> – 1.0.53-4
– Fix build issue (bug #1106101).
* Fri Jun 6 2014 Tim Waugh <twaugh@redhat.com> – 1.0.53-3
– Don’t use grep’s -P switch in pstopdf as it needs execmem (bug #1079534).
* Fri May 9 2014 Jiri Popelka <jpopelka@redhat.com> – 1.0.53-2
– Return Tim’s work-around patch for bug #768811.
* Mon Apr 28 2014 Jiri Popelka <jpopelka@redhat.com> – 1.0.53-1
– 1.0.53
* Wed Apr 2 2014 Jiri Popelka <jpopelka@redhat.com> – 1.0.41-6
– Remote command injection in cups-browsed (bug #1083327).
* Tue Mar 11 2014 Jiri Popelka <jpopelka@redhat.com> – 1.0.41-5
– Don’t ship pdftoopvp (#1027557) and urftopdf (#1002947).
——————————————————————————–
References:

[ 1 ] Bug #1199130 – CVE-2015-2265 cups-filters: remote command execution in remove_bad_chars() (incomplete fix for CVE-2014-2707)
https://bugzilla.redhat.com/show_bug.cgi?id=1199130
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update cups-filters’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorTomislav Protega
Cert idNCERT-REF-2015-03-0036-ADV
CveCVE-2015-2265 CVE-2014-2707
ID izvornikaFEDORA-2015-3036 FEDORA-2015-3003
Proizvodcups-filters
Izvorhttp://www.redhat.com
Top
More in Preporuke
Ranjivosti programske biblioteke libmspack

Otkriveno je nekoliko ranjivosti u programskoj biblioteci libmspack za Fedoru. Ranjivosti su posljedica čitanja memorije izvan granica spremnika te neispravne...

Close