--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-01127974ec
2024-09-28 01:26:49.812274
--------------------------------------------------------------------------------

Name        : cups-browsed
Product     : Fedora 40
Version     : 2.0.1
Release     : 3.fc40
URL         : https://github.com/OpenPrinting/cups-browsed
Summary     : Daemon for local auto-installation of remote printers
Description :
cups-browsed is a helper daemon, which automatically installs printers
locally, provides load balancing and clustering of print queues.
The daemon installs the printers based on found mDNS records and CUPS
broadcast, or by polling a remote print server.

--------------------------------------------------------------------------------
Update Information:

Fix for remote vulnerabilities against OpenPrinting cups-filters
--------------------------------------------------------------------------------
ChangeLog:

* Thu Sep 26 2024 Justin M. Forbes  - 1:2.0.1-2
- Fix for CVE-2024-47176
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2314997 - [Major Incident] CVE-2024-47176 cups-browsed: cups-browsed binds on UDP INADDR_ANY:631 trusting any packet from any source [fedora-40]
        https://bugzilla.redhat.com/show_bug.cgi?id=2314997
  [ 2 ] Bug #2315000 - [Major Incident] CVE-2024-47076 libcupsfilters: `cfGetPrinterAttributes` API does not perform sanitization on returned IPP attributes [fedora-40]
        https://bugzilla.redhat.com/show_bug.cgi?id=2315000
  [ 3 ] Bug #2315004 - [Major Incident] CVE-2024-47175 libppd: remote command injection via attacker controlled data in PPD file [fedora-40]
        https://bugzilla.redhat.com/show_bug.cgi?id=2315004
  [ 4 ] Bug #2315005 - [Major Incident] CVE-2024-47177 cups-filters: foomatic-rip in cups-filters allows arbitrary command execution via the FoomaticRIPCommandLine PPD parameter [fedora-40]
        https://bugzilla.redhat.com/show_bug.cgi?id=2315005
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-01127974ec' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue

Fedora 40: cups-browsed 2024-01127974ec Security Advisory Updates

September 28, 2024
Fix for remote vulnerabilities against OpenPrinting cups-filters

Summary

cups-browsed is a helper daemon, which automatically installs printers

locally, provides load balancing and clustering of print queues.

The daemon installs the printers based on found mDNS records and CUPS

broadcast, or by polling a remote print server.

Update Information:

Fix for remote vulnerabilities against OpenPrinting cups-filters

Change Log

* Thu Sep 26 2024 Justin M. Forbes - 1:2.0.1-2 - Fix for CVE-2024-47176

References

[ 1 ] Bug #2314997 - [Major Incident] CVE-2024-47176 cups-browsed: cups-browsed binds on UDP INADDR_ANY:631 trusting any packet from any source [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2314997 [ 2 ] Bug #2315000 - [Major Incident] CVE-2024-47076 libcupsfilters: `cfGetPrinterAttributes` API does not perform sanitization on returned IPP attributes [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2315000 [ 3 ] Bug #2315004 - [Major Incident] CVE-2024-47175 libppd: remote command injection via attacker controlled data in PPD file [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2315004 [ 4 ] Bug #2315005 - [Major Incident] CVE-2024-47177 cups-filters: foomatic-rip in cups-filters allows arbitrary command execution via the FoomaticRIPCommandLine PPD parameter [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2315005

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-01127974ec' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
Name : cups-browsed
Product : Fedora 40
Version : 2.0.1
Release : 3.fc40
URL : https://github.com/OpenPrinting/cups-browsed
Summary : Daemon for local auto-installation of remote printers

Related News