SciLinux: CVE-2007-4045 cups SL4.x i386/x86_64
Summary
Date: Wed, 7 Nov 2007 17:08:08 -0600Reply-To: Connie SiehSender: Security Errata for Scientific Linux From: Connie Sieh Subject: Security ERRATA for cups on SL4.x i386/x86_64Comments: To: scientific Synopsis: Important: cups security updateCVE Names: CVE-2007-4045 CVE-2007-4351 CVE-2007-4352 CVE-2007-5392 CVE-2007-5393Problem description:Alin Rad Pop discovered several flaws in the handling of PDF files. Anattacker could create a malicious PDF file that would cause CUPS to crashor potentially execute arbitrary code when printed.(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)Alin Rad Pop discovered a flaw in in the way CUPS handles certain IPP tags.A remote attacker who is able to connect to the IPP TCP port could send amalicious request causing the CUPS daemon to crash. (CVE-2007-4351)A flaw was found in the way CUPS handled SSL negotiation. A remote attackercapable of connecting to the CUPS daemon could cause CUPS to crash.(CVE-2007-4045)SL4.xSRPMS: cups-1.1.22-0.rc1.9.20.2.el4_5.2.src.rpmi386: cups-1.1.22-0.rc1.9.20.2.el4_5.2.i386.rpm cups-devel-1.1.22-0.rc1.9.20.2.el4_5.2.i386.rpm cups-libs-1.1.22-0.rc1.9.20.2.el4_5.2.i386.rpmx86_64: cups-1.1.22-0.rc1.9.20.2.el4_5.2.x86_64.rpm cups-devel-1.1.22-0.rc1.9.20.2.el4_5.2.x86_64.rpm cups-libs-1.1.22-0.rc1.9.20.2.el4_5.2.i386.rpm cups-libs-1.1.22-0.rc1.9.20.2.el4_5.2.x86_64.rpm-Connie Sieh-Troy Dawson