• [SECURITY] [DSA 5778-1] cups-filters security update

    From Salvatore Bonaccorso@21:1/5 to All on Sun Sep 29 17:20:01 2024
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-5778-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso September 29, 2024 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : cups-filters
    CVE ID : CVE-2024-47076 CVE-2024-47176
    Debian Bug : 1082820 1082827

    Simone Margaritelli reported several vulnerabilities in cups-filters.
    Missing validation of IPP attributes returned from an IPP server and
    multiple bugs in the cups-browsed component can result in the execution
    of arbitrary commands without authentication when a print job is
    started.

    For the stable distribution (bookworm), these problems have been fixed in version 1.28.17-3+deb12u1.

    We recommend that you upgrade your cups-filters packages.

    For the detailed security status of cups-filters please refer to its
    security tracker page at: https://security-tracker.debian.org/tracker/cups-filters

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmb5b6BfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0RqGA//VfGe41guaMVg8lIgwu9s3atSUeoUDZRf83XWQ0S6gvpTCG/Bko1KSgj0 xmzHlmjwFA2Sly5PhiWcqDp59txdXZymdojTXFebuE5MFqxcSLoIpn/vxZT6f3ky BdfK4oTXfJ5Au+KgRF+jC9zGiKgkMJfaCaf2PPFwan/4nXLYw/GIkvnYAecjGgEQ KjuzUgkItBVaGVeaInMISwfSISQFrMK80P7MJyX8ET2b71ijjpReAbfsuOQRaizj 5dnBXxCAE8l8A5VsZFUT1EK4m3Z7BgKKImnLqDdk61Mz+T7eC4R+Kv+rb5lLBMYK pPuBmYlH80U7bK4/TaivuWrX6FdHvtKGFUmQd+YO6rWofwrCTn/8+SlO8ZWOrjKx r7UDU7+XTnCu4DI87+7PBcqHEyQTG3CrK/RKblsfw0PP0DFtwJMiipuSjzBmNRZx nZppuug7Ks5dljAYGWFrBx2I29Qtj6MD4HeI4JKWoB3r3Xi1gX5vvsav4/r++s9Z GvINaqBBIytLjATxLYElCxA74MEmVFNPxUEeEq8xFyPGdnYquJ6xZ6wsy6x+O6Z2 T4ikIV5+FUA4v/c9JFdMj04dJXXaIfTcxBvYA4CoykdHmMGAw1/rCuucL4zoPMUl G03rz0k3/QziqZ6EM/Firbd++RrCo86wBiA10Anmhy7+0kS3TCE=
    =fH4o
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)