Connectiva Linux Security Announcement: cups Date: Thursday, April 04 2002 Topic: Security
Connectiva Linux Security Announcement: cups
DESCRIPTION CUPS (Common UNIX Printing System) is an open-source, freely available and cross-platform printing solution for UNIX environments.
The CUPS authors found two buffer overflows in the IPP code. These buffer overflows potentially could be exploited by a remote attacker whose IP address is allowed to access the CUPS server, allowing him/her to execute arbitrary code in that server.
This vulnerability[1] affects[2] all versions of CUPS prior to 1.1.4.
SOLUTION All users should do the upgrade. Please note that the printer daemon must be manually restarted after the upgrade. This can be done with the command shown below (executed as root):
ADDITIONAL INSTRUCTIONS Users of Conectiva Linux version 6.0 or higher may use apt to perform upgrades of RPM packages: - add the following line to /etc/apt/sources.list if it is not there yet (you may also use linuxconf to do this):