ELSA-2007-1020

ELSA-2007-1020 - Important: cups security and bug fix update

Type:SECURITY
Impact:IMPORTANT
Release Date:2007-10-31

Description


[1.2.4-11.14.el5_1.1]
- Applied patch to fix CVE-2007-4351 (STR #2561, bug #353981).

[1.2.4-11.14]
- Applied patch to fix cupsd crash when failing to open a file: URI
(STR #2351, bug #250415).

[1.2.4-11.13]
- Moved LSPP security attributes check before job creation (bug #231522).

[1.2.4-11.12]
- Moved LSPP access check before job creation (bug #231522).

[1.2.4-11.11]
- Better error checking in the LSPP patch (bug #231522).

[1.2.4-11.10]
- Applied patch to fix CVE-2007-3387 (bug #248223).

[1.2.4-11.9]
- Fixed IPv6 address parsing (bug #241400, STR #2117).
- Fixed a bug that caused cups-lpd not to set the correct value for
job-originating-host-name (bug #240223, STR #2023).
- Cleaned up initscript error handling (bug #237953).
- Fixed cups-lpd -odocument-format=... option (bug #230073, STR #2266).
- Fixed If-Modified-Since: handling in libcups (bug #218764, STR #2133).
- Make the initscript use start priority 56 (bug #213828).

[1.2.4-11.8]
- Applied fix for STR #2264 (bug #230118).
- Added patch for UNIX domain sockets authentication (bug #230613).
- LSPP: Updated patch for line-wrapped labels (bug #228107).

[1.2.4-11.7]
- Don't reload CUPS after rotating the logs with logrotate, but make sure
to use the new file in that case (bug #215024).

[1.2.4-11.6]
- LSPP: added check_context() function for get_jobs(), get_job_attrs() and
validate_user() (bug #229673).
- Fixed a potential scheduler crash (bug #231522).


Related CVEs


CVE-2007-4351

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 5 (i386) cups-1.2.4-11.14.el5_1.1.src.rpm2570fb91bf3bbedeaaaa8a8eb5813dea2c5294dac59d691a5e22e8f1f459e26dELBA-2015-0064el5_ga_i386_patch
cups-1.2.4-11.14.el5_1.1.i386.rpme6b6ded3d65f57e2f50717aa89fa1dc9d6525c7da5c62cff39312d29b4db2c19ELBA-2015-0064el5_ga_i386_patch
cups-devel-1.2.4-11.14.el5_1.1.i386.rpm73671150382e74077e8490cc7a6548ca1ef8832c417ab2fd6b266b934b49fd3bELBA-2015-0064el5_ga_i386_patch
cups-libs-1.2.4-11.14.el5_1.1.i386.rpm26e3e44aded81585c9689c4e5fa856ebfa5e0bd6c4c422a60259734f978ab6e1ELBA-2015-0064el5_ga_i386_patch
cups-lpd-1.2.4-11.14.el5_1.1.i386.rpm97a88109119bbb2d55c7877af05ee28747d189b7e7a99adfe5336d464cc321ecELBA-2015-0064el5_ga_i386_patch
Oracle Linux 5 (x86_64) cups-1.2.4-11.14.el5_1.1.src.rpm2570fb91bf3bbedeaaaa8a8eb5813dea2c5294dac59d691a5e22e8f1f459e26dELBA-2015-0064el5_ga_x86_64_patch
cups-1.2.4-11.14.el5_1.1.x86_64.rpm7900499003a2739455a06b1b3a3804f34e077ea9470502322784d2150bfe372eELBA-2015-0064el5_ga_x86_64_patch
cups-devel-1.2.4-11.14.el5_1.1.i386.rpm73671150382e74077e8490cc7a6548ca1ef8832c417ab2fd6b266b934b49fd3bELBA-2015-0064el5_ga_x86_64_patch
cups-devel-1.2.4-11.14.el5_1.1.x86_64.rpme1953a8dbae1b17b68780c4c0436c9c23159593aa0b776d5ea817ec384f0d363ELBA-2015-0064el5_ga_x86_64_patch
cups-libs-1.2.4-11.14.el5_1.1.i386.rpm26e3e44aded81585c9689c4e5fa856ebfa5e0bd6c4c422a60259734f978ab6e1ELBA-2015-0064el5_ga_x86_64_patch
cups-libs-1.2.4-11.14.el5_1.1.x86_64.rpm65cdfaa34408900be4b7cc7192fa9e4429ab2a9f2685748add2fb96e22ee54acELBA-2015-0064el5_ga_x86_64_patch
cups-lpd-1.2.4-11.14.el5_1.1.x86_64.rpmd3d6fddb82e576f3cfe7202a0d9a6fce896b4f5fbfbd3c3cba91e9ac7ea3ac8fELBA-2015-0064el5_ga_x86_64_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete