Date:         Wed, 7 Nov 2007 17:08:08 -0600
Reply-To:     Connie Sieh 
Sender:       Security Errata for Scientific Linux
              
From:         Connie Sieh 
Subject:      Security ERRATA for cups on SL4.x i386/x86_64
Comments: To: scientific 

Synopsis:          Important: cups security update

CVE Names:         CVE-2007-4045
 		   CVE-2007-4351
                    CVE-2007-4352
                    CVE-2007-5392
                    CVE-2007-5393

Problem description:

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause CUPS to crash
or potentially execute arbitrary code when printed.
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

Alin Rad Pop discovered a flaw in in the way CUPS handles certain IPP tags.
A remote attacker who is able to connect to the IPP TCP port could send a
malicious request causing the CUPS daemon to crash. (CVE-2007-4351)

A flaw was found in the way CUPS handled SSL negotiation. A remote attacker
capable of connecting to the CUPS daemon could cause CUPS to crash.
(CVE-2007-4045)

SL4.x

SRPMS:
 	cups-1.1.22-0.rc1.9.20.2.el4_5.2.src.rpm

i386:
 	cups-1.1.22-0.rc1.9.20.2.el4_5.2.i386.rpm
 	cups-devel-1.1.22-0.rc1.9.20.2.el4_5.2.i386.rpm
 	cups-libs-1.1.22-0.rc1.9.20.2.el4_5.2.i386.rpm

x86_64:
 	cups-1.1.22-0.rc1.9.20.2.el4_5.2.x86_64.rpm
 	cups-devel-1.1.22-0.rc1.9.20.2.el4_5.2.x86_64.rpm
 	cups-libs-1.1.22-0.rc1.9.20.2.el4_5.2.i386.rpm
 	cups-libs-1.1.22-0.rc1.9.20.2.el4_5.2.x86_64.rpm

-Connie Sieh
-Troy Dawson

SciLinux: CVE-2007-4045 cups SL4.x i386/x86_64

Important: cups security update

Summary

Date:         Wed, 7 Nov 2007 17:08:08 -0600Reply-To:     Connie Sieh Sender:       Security Errata for Scientific Linux              From:         Connie Sieh Subject:      Security ERRATA for cups on SL4.x i386/x86_64Comments: To: scientific Synopsis:          Important: cups security updateCVE Names:         CVE-2007-4045 		   CVE-2007-4351                    CVE-2007-4352                    CVE-2007-5392                    CVE-2007-5393Problem description:Alin Rad Pop discovered several flaws in the handling of PDF files. Anattacker could create a malicious PDF file that would cause CUPS to crashor potentially execute arbitrary code when printed.(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)Alin Rad Pop discovered a flaw in in the way CUPS handles certain IPP tags.A remote attacker who is able to connect to the IPP TCP port could send amalicious request causing the CUPS daemon to crash. (CVE-2007-4351)A flaw was found in the way CUPS handled SSL negotiation. A remote attackercapable of connecting to the CUPS daemon could cause CUPS to crash.(CVE-2007-4045)SL4.xSRPMS: 	cups-1.1.22-0.rc1.9.20.2.el4_5.2.src.rpmi386: 	cups-1.1.22-0.rc1.9.20.2.el4_5.2.i386.rpm 	cups-devel-1.1.22-0.rc1.9.20.2.el4_5.2.i386.rpm 	cups-libs-1.1.22-0.rc1.9.20.2.el4_5.2.i386.rpmx86_64: 	cups-1.1.22-0.rc1.9.20.2.el4_5.2.x86_64.rpm 	cups-devel-1.1.22-0.rc1.9.20.2.el4_5.2.x86_64.rpm 	cups-libs-1.1.22-0.rc1.9.20.2.el4_5.2.i386.rpm 	cups-libs-1.1.22-0.rc1.9.20.2.el4_5.2.x86_64.rpm-Connie Sieh-Troy Dawson



Security Fixes

Severity

Related News