Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: cups
Date: Mon, 30 Dec 2002 02:47:45
Message-Id: 20021229133516.3D1C933806@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200212-13
6 - - --------------------------------------------------------------------
7
8 PACKAGE : cups
9 SUMMARY : multiple cups vulnerbilities
10 DATE    : 2002-12-29 13:12 UTC
11 EXPLOIT : remote and local
12
13 - - --------------------------------------------------------------------
14
15 - From iDEFENSE advisory:
16
17 "Exploitation of multiple CUPS vulnerabilities allow local and remote
18 attackers in the worst of the scenarios to gain root privileges."
19
20 Read the full advisory at
21 http://www.idefense.com/advisory/12.19.02.txt
22
23 SOLUTION
24
25 It is recommended that all Gentoo Linux users who are running
26 net-print/cups-1.1.17_pre20021025 or earlier update their systems as
27 follows:
28
29 emerge rsync
30 emerge cups
31 emerge clean
32
33 - - --------------------------------------------------------------------
34 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
35 lordvan@g.o
36 - - --------------------------------------------------------------------
37 -----BEGIN PGP SIGNATURE-----
38 Version: GnuPG v1.2.1 (GNU/Linux)
39
40 iD8DBQE+DvoLfT7nyhUpoZMRAh8YAJ4lvCiGG5XfVvbpoKfzkKvj0geBygCeJRh1
41 XYhpQT4S3rWtJu33t3ouuSI=
42 =Qel0
43 -----END PGP SIGNATURE-----