[ubuntu/jaunty-security] cups_1.3.9-17ubuntu3.6_ia64_translations.tar.gz, cups_1.3.9-17ubuntu3.6_lpia_translations.tar.gz, cups_1.3.9-17ubuntu3.6_amd64_translations.tar.gz, cups_1.3.9-17ubuntu3.6_armel_translations.tar.gz, cups_1.3.9-17ubuntu3.6_sparc_translations.tar.gz (delayed), cups_1.3.9-17ubuntu3.6_hppa_translations.tar.gz, cups_1.3.9-17ubuntu3.6_powerpc_translations.tar.gz, cups_1.3.9-17ubuntu3.6_i386_translations.tar.gz, cups 1.3.9-17ubuntu3.6 (Accepted)

Ubuntu Installer archive at ubuntu.com
Wed Mar 3 20:04:38 GMT 2010


cups (1.3.9-17ubuntu3.6) jaunty-security; urgency=low

  * SECURITY UPDATE: denial of service via use-after-free
    - debian/patches/CVE-2009-3553.dpatch: check fdptr->use and
      cupsd_inactive_fds in scheduler/select.c.
    - CVE-2009-3553
    - CVE-2010-0302
  * SECURITY UPDATE: privilege escalation via lppasswd tool
    - debian/patches/CVE-2010-0393.dpatch: don't allow environment
      variables to override directories in cups/globals.c and
      systemv/lppasswd.c.
    - CVE-2010-0393

Date: Thu, 25 Feb 2010 10:54:47 -0500
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/jaunty/+source/cups/1.3.9-17ubuntu3.6
-------------- next part --------------
Format: 1.8
Date: Thu, 25 Feb 2010 10:54:47 -0500
Source: cups
Binary: libcups2 libcupsimage2 cups cups-client libcups2-dev libcupsimage2-dev cups-bsd cups-common cups-dbg cupsys cupsys-client cupsys-common cupsys-bsd cupsys-dbg libcupsys2 libcupsys2-dev
Architecture: source
Version: 1.3.9-17ubuntu3.6
Distribution: jaunty-security
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 cups       - Common UNIX Printing System(tm) - server
 cups-bsd   - Common UNIX Printing System(tm) - BSD commands
 cups-client - Common UNIX Printing System(tm) - client programs (SysV)
 cups-common - Common UNIX Printing System(tm) - common files
 cups-dbg   - Common UNIX Printing System(tm) - debugging symbols
 cupsys     - Common UNIX Printing System (transitional package)
 cupsys-bsd - Common UNIX Printing System (transitional package)
 cupsys-client - Common UNIX Printing System (transitional package)
 cupsys-common - Common UNIX Printing System (transitional package)
 cupsys-dbg - Common UNIX Printing System (transitional package)
 libcups2   - Common UNIX Printing System(tm) - libs
 libcups2-dev - Common UNIX Printing System(tm) - development files
 libcupsimage2 - Common UNIX Printing System(tm) - image libs
 libcupsimage2-dev - Common UNIX Printing System(tm) - image development files
 libcupsys2 - Common UNIX Printing System (transitional package)
 libcupsys2-dev - Common UNIX Printing System (transitional package)
Changes: 
 cups (1.3.9-17ubuntu3.6) jaunty-security; urgency=low
 .
   * SECURITY UPDATE: denial of service via use-after-free
     - debian/patches/CVE-2009-3553.dpatch: check fdptr->use and
       cupsd_inactive_fds in scheduler/select.c.
     - CVE-2009-3553
     - CVE-2010-0302
   * SECURITY UPDATE: privilege escalation via lppasswd tool
     - debian/patches/CVE-2010-0393.dpatch: don't allow environment
       variables to override directories in cups/globals.c and
       systemv/lppasswd.c.
     - CVE-2010-0393
Checksums-Sha1: 
 03ca28a763ecfc9f619b783036ca1476114aed0d 1995 cups_1.3.9-17ubuntu3.6.dsc
 44d80b59a1d8223f16878459a765efcfa742f7b6 335789 cups_1.3.9-17ubuntu3.6.diff.gz
Checksums-Sha256: 
 f70e2640eaa972a3598d807237dc7e69561427fe71eddc9c1a49f5fd14abe85f 1995 cups_1.3.9-17ubuntu3.6.dsc
 f0716f80fb4bef7df00c50c7b254da3aeec270619f68cccd5d5fa21f61db624b 335789 cups_1.3.9-17ubuntu3.6.diff.gz
Files: 
 e338a99e7a2e02a57415885e285f3bb1 1995 net optional cups_1.3.9-17ubuntu3.6.dsc
 4f5f61340c4875048c60d69f82dec645 335789 net optional cups_1.3.9-17ubuntu3.6.diff.gz
Original-Maintainer: Debian CUPS Maintainers <pkg-cups-devel at lists.alioth.debian.org>


More information about the Jaunty-changes mailing list