ELSA-2014-1388

ELSA-2014-1388 - cups security and bug fix update

Type:SECURITY
Impact:MODERATE
Release Date:2014-10-15

Description


[1:1.4.2-67]
- Revert change to whitelist /rss/ resources, as this was not used
upstream.

[1:1.4.2-66]
- More STR #4461 fixes from upstream: make rss feeds world-readable,
but cachedir private.
- Fix icon display in web interface during server restart (STR #4475).

[1:1.4.2-65]
- Fixes for upstream patch for STR #4461: allow /rss/ requests for
files we created.

[1:1.4.2-64]
- Use upstream patch for STR #4461.

[1:1.4.2-63]
- Applied upstream patch to fix CVE-2014-5029 (bug #1122600),
CVE-2014-5030 (bug #1128764), CVE-2014-5031 (bug #1128767).
- Fix conf/log file reading for authenticated users (STR #4461).

[1:1.4.2-62]
- Fix CGI handling (STR #4454, bug #1120419).

[1:1.4.2-61]
- fix patch for CVE-2014-3537 (bug #1117794)

[1:1.4.2-60]
- CVE-2014-2856: cross-site scripting flaw (bug #1117798)
- CVE-2014-3537: insufficient checking leads to privilege escalation (bug #1117794)

[1:1.4.2-59]
- Removed package description changes.

[1:1.4.2-58]
- Applied patch to fix 'Bad request' errors as a result of adding in
httpSetTimeout (STR #4440, also part of svn revision 9967).

[1:1.4.2-57]
- Fixed timeout issue with cupsd reading when there is no data ready
(bug #1110045).

[1:1.4.2-56]
- Fixed synconclose patch to avoid 'too many arguments for format' warning.
- Fixed settimeout patch to include math.h for fmod declaration.

[1:1.4.2-55]
- Fixed typo preventing web interface from changing driver (bug #1104483,
STR #3601).
- Fixed SyncOnClose patch (bug #984883).

[1:1.4.2-54]
- Use upstream patch to avoid replaying GSS credentials (bug #1040293).

[1:1.4.2-53]
- Prevent BrowsePoll problems across suspend/resume (bug #769292):
- Eliminate indefinite wait for response (svn revision 9688).
- Backported httpSetTimeout API function from CUPS 1.5 and use it in
the ipp backend so that we wait indefinitely until the printer
responds, we get a hard error, or the job is cancelled.
- cups-polld: reconnect on error.
- Added new SyncOnClose directive to use fsync() after altering
configuration files: defaults to 'Yes'. Adjust in cupsd.conf (bug #984883).
- Fix cupsctl man page typo (bug #1011076).
- Use more portable rpm specfile syntax for conditional php building
(bug #988598).
- Fix SetEnv directive in cupsd.conf (bug #986495).
- Fix 'collection' attribute sending (bug #978387).
- Prevent format_log segfault (bug #971079).
- Prevent stringpool corruption (bug #884851).
- Don't crash when job queued for printer that times out (bug #855431).
- Upstream patch for broken multipart handling (bug #852846).
- Install /etc/cron.daily/cups with correct permissions (bug #1012482).


Related CVEs


CVE-2014-3537
CVE-2014-5031
CVE-2014-5030
CVE-2014-5029
CVE-2014-2856

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 6 (i386) cups-1.4.2-67.el6.src.rpm770e3f8fa94cd10a172b87fc97d0a0dc26650d4aa0284402d0e116042bec02cbELBA-2019-0716ol6_i386_latest_archive
cups-1.4.2-67.el6.src.rpm770e3f8fa94cd10a172b87fc97d0a0dc26650d4aa0284402d0e116042bec02cbELBA-2019-0716ol6_u6_i386_base
cups-1.4.2-67.el6.i686.rpm83c20328c6a648c8559355db69ddbf1128e7c1c74d9e2f9db48350b688190d87ELBA-2019-0716ol6_i386_latest_archive
cups-1.4.2-67.el6.i686.rpm83c20328c6a648c8559355db69ddbf1128e7c1c74d9e2f9db48350b688190d87ELBA-2019-0716ol6_u6_i386_base
cups-devel-1.4.2-67.el6.i686.rpm49dd1f825ffafeec4e0b85321ef4307ee6d2f8c55ca96c0d0fa5cc19739d62dfELBA-2019-0716ol6_i386_latest_archive
cups-devel-1.4.2-67.el6.i686.rpm49dd1f825ffafeec4e0b85321ef4307ee6d2f8c55ca96c0d0fa5cc19739d62dfELBA-2019-0716ol6_u6_i386_base
cups-libs-1.4.2-67.el6.i686.rpmad296d6385d14e19afc69638e746746f50980ea0f4f8e0e0a6b8350473a2f63fELBA-2019-0716ol6_i386_latest_archive
cups-libs-1.4.2-67.el6.i686.rpmad296d6385d14e19afc69638e746746f50980ea0f4f8e0e0a6b8350473a2f63fELBA-2019-0716ol6_u6_i386_base
cups-lpd-1.4.2-67.el6.i686.rpm72a9f108d96cc02f67af66950ec8b848be8514af59b26038eca76b26e0cba9baELBA-2019-0716ol6_i386_latest_archive
cups-lpd-1.4.2-67.el6.i686.rpm72a9f108d96cc02f67af66950ec8b848be8514af59b26038eca76b26e0cba9baELBA-2019-0716ol6_u6_i386_base
cups-php-1.4.2-67.el6.i686.rpm5c146676b3dac57ec3734a8f861a26bbcc7678fa69db8e7e81bcece1a1b32407ELBA-2019-0716ol6_i386_latest_archive
cups-php-1.4.2-67.el6.i686.rpm5c146676b3dac57ec3734a8f861a26bbcc7678fa69db8e7e81bcece1a1b32407ELBA-2019-0716ol6_u6_i386_base
Oracle Linux 6 (x86_64) cups-1.4.2-67.el6.src.rpm770e3f8fa94cd10a172b87fc97d0a0dc26650d4aa0284402d0e116042bec02cbELBA-2019-0716ol6_u6_x86_64_base
cups-1.4.2-67.el6.src.rpm770e3f8fa94cd10a172b87fc97d0a0dc26650d4aa0284402d0e116042bec02cbELBA-2019-0716ol6_x86_64_latest_archive
cups-1.4.2-67.el6.x86_64.rpm86138095a5aa16346263cf1cff4a60460b156da8184f1253c02c8ebab7512f34ELBA-2019-0716ol6_u6_x86_64_base
cups-1.4.2-67.el6.x86_64.rpm86138095a5aa16346263cf1cff4a60460b156da8184f1253c02c8ebab7512f34ELBA-2019-0716ol6_x86_64_latest_archive
cups-devel-1.4.2-67.el6.i686.rpm49dd1f825ffafeec4e0b85321ef4307ee6d2f8c55ca96c0d0fa5cc19739d62dfELBA-2019-0716ol6_u6_x86_64_base
cups-devel-1.4.2-67.el6.i686.rpm49dd1f825ffafeec4e0b85321ef4307ee6d2f8c55ca96c0d0fa5cc19739d62dfELBA-2019-0716ol6_x86_64_latest_archive
cups-devel-1.4.2-67.el6.x86_64.rpm4e8250bf908c21b392a86b80518b68382e37138429c5a4de3b20694aa4b49bb6ELBA-2019-0716ol6_u6_x86_64_base
cups-devel-1.4.2-67.el6.x86_64.rpm4e8250bf908c21b392a86b80518b68382e37138429c5a4de3b20694aa4b49bb6ELBA-2019-0716ol6_x86_64_latest_archive
cups-libs-1.4.2-67.el6.i686.rpmad296d6385d14e19afc69638e746746f50980ea0f4f8e0e0a6b8350473a2f63fELBA-2019-0716ol6_u6_x86_64_base
cups-libs-1.4.2-67.el6.i686.rpmad296d6385d14e19afc69638e746746f50980ea0f4f8e0e0a6b8350473a2f63fELBA-2019-0716ol6_x86_64_latest_archive
cups-libs-1.4.2-67.el6.x86_64.rpm21256008c014a2ffbf3a88a538594fed0f0dfe2c25700eb2805228792eca20ebELBA-2019-0716ol6_u6_x86_64_base
cups-libs-1.4.2-67.el6.x86_64.rpm21256008c014a2ffbf3a88a538594fed0f0dfe2c25700eb2805228792eca20ebELBA-2019-0716ol6_x86_64_latest_archive
cups-lpd-1.4.2-67.el6.x86_64.rpmdc0384f1f3ca184ddb717efa47f5b4eb622762cf7feb7ceb91a9a4dc9b898456ELBA-2019-0716ol6_u6_x86_64_base
cups-lpd-1.4.2-67.el6.x86_64.rpmdc0384f1f3ca184ddb717efa47f5b4eb622762cf7feb7ceb91a9a4dc9b898456ELBA-2019-0716ol6_x86_64_latest_archive
cups-php-1.4.2-67.el6.x86_64.rpmd6f34e534803cc8e54c6a1e9b57ea017cdd438e75719642acf0802419e533f88ELBA-2019-0716ol6_u6_x86_64_base
cups-php-1.4.2-67.el6.x86_64.rpmd6f34e534803cc8e54c6a1e9b57ea017cdd438e75719642acf0802419e533f88ELBA-2019-0716ol6_x86_64_latest_archive



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete