Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: cups (200306-09)
Date: Sun, 15 Jun 2003 19:33:19
Message-Id: 20030614210113.6BD113378F@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200306-09
6 - - - ---------------------------------------------------------------------
7
8           PACKAGE : cups
9           SUMMARY : Denial of service
10              DATE : 2003-06-14 21:01 UTC
11           EXPLOIT : remote
12 VERSIONS AFFECTED : <cups-1.1.18-r5
13     FIXED VERSION : >=cups-1.1.18-r5
14               CVE : CAN-2003-0195
15
16 - - - ---------------------------------------------------------------------
17
18 CUPS allows remote attackers to cause a denial of service via a partial
19 printing request to the IPP port (631), which does not time out.
20
21 SOLUTION
22
23 It is recommended that all Gentoo Linux users who are running
24 net-print/cups upgrade to cups-1.1.18-r5 as follows
25
26 emerge sync
27 emerge cups
28 emerge clean
29
30 - - - ---------------------------------------------------------------------
31 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
32 - - - ---------------------------------------------------------------------
33 -----BEGIN PGP SIGNATURE-----
34 Version: GnuPG v1.2.2 (GNU/Linux)
35
36 iD8DBQE+640YfT7nyhUpoZMRApGFAJ9VN5VsZ5X8Hyax83vLTNeRhJSknwCfcwT7
37 uBDqm8aolqlHdjlhobiu+8c=
38 =8kiT
39 -----END PGP SIGNATURE-----