ELSA-2010-0754

ELSA-2010-0754 - cups security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2010-10-07

Description



[1:1.1.17-13.3.70]
- Reinstated fix for CVE-2010-3702 (bug #595245).

[1:1.1.17-13.3.69]
- Temporarily removed fix for CVE-2010-3702.

[1:1.1.17-13.3.68]
- Added bounds checking to Type1CFontFile::getWord() in order to
verify fix for CVE-2010-3702.
- Applied small fix to CVE-2009-0791 change: allow objSize=0 in
gmallocCn() if C > 0. As well as being correct, this aids with
testing the fix for CVE-2010-3702.

[1:1.1.17-13.3.67]
- Applied upstream patch to fix uninitialized Gfx::parser pointer
dereference (bug #595245).


Related CVEs



Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 3 (i386) cups-1.1.17-13.3.70.src.rpmb096708eb7385374a8558dd37c93f82e-
cups-1.1.17-13.3.70.i386.rpmc42eea84c866814218fbaa07e66f43e4-
cups-devel-1.1.17-13.3.70.i386.rpm5f9b7e7164fea2c47477b13c0a6ac2f4-
cups-libs-1.1.17-13.3.70.i386.rpm4879330e088693f45d319091a1e73a56-
Oracle Linux 3 (x86_64) cups-1.1.17-13.3.70.src.rpmb096708eb7385374a8558dd37c93f82e-
cups-1.1.17-13.3.70.x86_64.rpm04d963f688093995730316e926f441a8-
cups-devel-1.1.17-13.3.70.x86_64.rpm19f95fdcadfb0b0a714fe2fc35ebc15d-
cups-libs-1.1.17-13.3.70.i386.rpm4879330e088693f45d319091a1e73a56-
cups-libs-1.1.17-13.3.70.x86_64.rpmc2e3b0d2e5cc08af5c89758c62941f74-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete