Freedom The Open Source Way Contribute Articles or News to OSForgeOSForge HomeLogout from Forums
Contacting OSForgeOSForge HomeAbout OSForge
  

Root
Contribute News
Learning Corner
Linux Distributions
Linux Common FAQ's
Discussion Forums
Community Gallery
Links Directory
Search OSForge
Networking
Industry Updates
Linux & Open Source
Opinions
Press Release
Programming
Security
Web Development

White Paper
Zenoss Expands IT Management Solution for Managed Service Providers
Moab Workload Manager Claims Title as World’s First Petaflop Scheduler
Moab Workload Manager Claims Title as World’s First Petaflop Scheduler
xTuple ERP Exceeds 100,000 Downloads, Readies Version 3.0 Beta
Open-Xchange to Deliver Collaboration Solution Integrated With Parallels Automation
OpenKM - Document Mangement announces version 2.0
SugarCRM Manages End-to-End SaaS Offering with Zenoss
Linux Foundation’s Annual Collaboration Summit Kicks Off
Engine Yard Kicks Off Hackfest Series for Ruby Developers

View More »

Connectiva Linux Security Announcement: cups
By : Eric Lim [www] Find more article by Eric Lim on Security
Thursday the 4th, April 2002 at 03:51 AM (EST)
Send this Story to a Friend Readers TalkBack (0) - 395 Reads

Printer Friendly Page Printable format
Send this Story to a Friend Foward to Email

Connectiva Linux Security Announcement: cups

DESCRIPTION
CUPS (Common UNIX Printing System) is an open-source, freely
available and cross-platform printing solution for UNIX
environments.

The CUPS authors found two buffer overflows in the IPP code. These
buffer overflows potentially could be exploited by a remote attacker
whose IP address is allowed to access the CUPS server, allowing
him/her to execute arbitrary code in that server.

This vulnerability[1] affects[2] all versions of CUPS prior to 1.1.4.


SOLUTION
All users should do the upgrade. Please note that the printer daemon
must be manually restarted after the upgrade. This can be done with
the command shown below (executed as root):

# service cups restart


REFERENCES:
1.http://online.securityfocus.com/bid/4100
2.http://www.cups.org/relnotes.html#01011400


DIRECT DOWNLOAD LINKS TO THE UPDATED PACKAGES
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/cups-1.1.14-1U60_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/cups-devel-1.1.14-1U60_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/cups-libs-1.1.14-1U60_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/SRPMS/cups-1.1.14-1U60_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/cups-1.1.14-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/cups-devel-1.1.14-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/cups-devel-static-1.1.14-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/cups-doc-1.1.14-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/cups-libs-1.1.14-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/SRPMS/cups-1.1.14-1U70_1cl.src.rpm

ADDITIONAL INSTRUCTIONS
Users of Conectiva Linux version 6.0 or higher may use apt to perform
upgrades of RPM packages:
- add the following line to /etc/apt/sources.list if it is not there yet
   (you may also use linuxconf to do this):

rpm [cncbr] ftp://atualizacoes.conectiva.com.br 6.0/conectiva updates

(replace 6.0 with the correct version number if you are not running CL6.0)

- run:                 apt-get update
- after that, execute: apt-get upgrade

Detailed instructions reagarding the use of apt and upgrade examples
can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en


- -------------------------------------------------------------------------
All packages are signed with Conectiva's GPG key. The key and instructions
on how to import it can be found at
http://distro.conectiva.com.br/seguranca/chave/?idioma=en
Instructions on how to check the signatures of the RPM packages can be
found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en
- -------------------------------------------------------------------------
All our advisories and generic update instructions can be viewed at
http://distro.conectiva.com.br/atualizacoes/?idioma=en

- -------------------------------------------------------------------------
subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br
unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE8qwqU42jd0JmAcZARAtYKAKDmjmd1ZQ724Fk/Na4T4s0X+MU9cgCfSb5o
qkfB7w6jvpr/SzkscoJ1dA4=
=VB5q
-----END PGP SIGNATURE-----

  
Reader Rating from 1-5

 

Poor very 

1

2

3

4

5
 very Excellent

Talkback

Post Your Talkback | View All Talkback (0 Posted)


 Currently there are no Talkback posted on "Connectiva Linux Security Announcement: cups", Click here to be the first to post a talkback.


 
Scroll Up

   About | Term of Use | Privacy | Contact us | Tell a Friend | Advertise  

OSForge News RSS Feed