ELSA-2008-0161

ELSA-2008-0161 - Important: cups security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2008-02-25

Description


[1.1.22-0.rc1.9.20.2:.5]
- Prevented invalid memory accesses when a class and its singleton printer
are timed out in the same sweep (CVE-2008-0597, bug #433828).
- Back-ported mimeDeleteType from 1.2.x (CVE-2008-0596, bug #433828).

[1.1.22-0.rc1.9.20.2:.4]
- Prevent double-free when a browsed class has the same name as a printer
or vice versa (bug #433764, STR #2656).
- Reverted previous change as no security impact (bug #418371).

[1.1.22-0.rc1.9.20.2:.3]
- Applied patch to fix CVE-2007-5848 (bug #418371).


Related CVEs


CVE-2008-0596
CVE-2008-0597

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 4 (i386) cups-1.1.22-0.rc1.9.20.2.el4_6.5.src.rpmedaa1b02eb3f6f42776ba337f10b412bELSA-2010-0755
cups-1.1.22-0.rc1.9.20.2.el4_6.5.i386.rpm0916a98a15800b52b189ed6667b17e1eELSA-2010-0755
cups-devel-1.1.22-0.rc1.9.20.2.el4_6.5.i386.rpm85e3c7bf0bcd3931643ae0813ad5d317ELSA-2010-0755
cups-libs-1.1.22-0.rc1.9.20.2.el4_6.5.i386.rpm34e22d1ec0117f6213cca4a8864800ecELSA-2010-0755
Oracle Linux 4 (x86_64) cups-1.1.22-0.rc1.9.20.2.el4_6.5.src.rpmedaa1b02eb3f6f42776ba337f10b412bELSA-2010-0755
cups-1.1.22-0.rc1.9.20.2.el4_6.5.x86_64.rpmbb4481b7d0330a6abeac886724f70ee1ELSA-2010-0755
cups-devel-1.1.22-0.rc1.9.20.2.el4_6.5.x86_64.rpma761f43002cf29c93dd3a7b7e98aee5cELSA-2010-0755
cups-libs-1.1.22-0.rc1.9.20.2.el4_6.5.i386.rpm34e22d1ec0117f6213cca4a8864800ecELSA-2010-0755
cups-libs-1.1.22-0.rc1.9.20.2.el4_6.5.x86_64.rpmbdb4482dafdfbe307c37da5e0e2d5aafELSA-2010-0755



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete