[ubuntu/oracular-proposed] cups 2.4.10-1ubuntu2 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Fri Sep 27 15:30:36 UTC 2024


cups (2.4.10-1ubuntu2) oracular; urgency=medium

  * SECURITY UPDATE: PPD injection issues (LP: #2082335)
    - debian/patches/sec-202409-1.patch: validate URIs, attribute names,
      and capabilities in cups/ppd-cache.c, scheduler/ipp.c.
    - debian/patches/sec-202409-2.patch: sanitize make and model in
      cups/ppd-cache.c.
    - debian/patches/sec-202409-3.patch: PPDize preset and template names
      in cups/ppd-cache.c.
    - debian/patches/sec-202409-4.patch: quote PPD localized strings in
      cups/ppd-cache.c.
    - debian/patches/sec-202409-5.patch: fix warnings in cups/ppd-cache.c.
    - CVE-2024-47175

Date: Thu, 26 Sep 2024 07:14:15 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/cups/2.4.10-1ubuntu2
-------------- next part --------------
Format: 1.8
Date: Thu, 26 Sep 2024 07:14:15 -0400
Source: cups
Built-For-Profiles: noudeb
Architecture: source
Version: 2.4.10-1ubuntu2
Distribution: oracular
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Launchpad-Bugs-Fixed: 2082335
Changes:
 cups (2.4.10-1ubuntu2) oracular; urgency=medium
 .
   * SECURITY UPDATE: PPD injection issues (LP: #2082335)
     - debian/patches/sec-202409-1.patch: validate URIs, attribute names,
       and capabilities in cups/ppd-cache.c, scheduler/ipp.c.
     - debian/patches/sec-202409-2.patch: sanitize make and model in
       cups/ppd-cache.c.
     - debian/patches/sec-202409-3.patch: PPDize preset and template names
       in cups/ppd-cache.c.
     - debian/patches/sec-202409-4.patch: quote PPD localized strings in
       cups/ppd-cache.c.
     - debian/patches/sec-202409-5.patch: fix warnings in cups/ppd-cache.c.
     - CVE-2024-47175
Checksums-Sha1:
 2f8bea1d23458881582725f7061e92255e66cbb4 3203 cups_2.4.10-1ubuntu2.dsc
 8a5fcc484d65266624d10b0b2c8b9441f28d5f39 401132 cups_2.4.10-1ubuntu2.debian.tar.xz
 13511db4a5973fb293d6218a7a1648771a6e3b78 11452 cups_2.4.10-1ubuntu2_source.buildinfo
Checksums-Sha256:
 d8006cb79b5edaca5f3c1fb3f841e50af7375527610e13862cedf4bed23e16f1 3203 cups_2.4.10-1ubuntu2.dsc
 9ff93d200f978fc1b131da8b86f6a7a9dc550df64642c8a4ec9dacdae80a8eb8 401132 cups_2.4.10-1ubuntu2.debian.tar.xz
 cb8e0a73c8c32ef5a2bfe346de6c4448c0d990abaef79ac4c87ac7d7aa5f5a7d 11452 cups_2.4.10-1ubuntu2_source.buildinfo
Files:
 31dc7f513e7b5a44b3a89f4b669c9498 3203 net optional cups_2.4.10-1ubuntu2.dsc
 2924761f6285a04eef25a69a7efe5aa9 401132 net optional cups_2.4.10-1ubuntu2.debian.tar.xz
 2572e86b0a733154bda23a2ad424a90a 11452 net optional cups_2.4.10-1ubuntu2_source.buildinfo
Original-Maintainer: Debian Printing Team <debian-printing at lists.debian.org>


More information about the oracular-changes mailing list