SciLinux: CVE-2007-4351 cups SL5.x i386/x86_64
Summary
Date: Wed, 31 Oct 2007 15:15:59 -0500Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for cups on SL5.x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis: Important: cups security and bug fix updateIssue date: 2007-10-31CVE Names: CVE-2007-4351A flaw was found in the way CUPS handles certain Internet Printing Protocol(IPP) tags. A remote attacker who is able to connect to the IPP TCP portcould send a malicious request causing the CUPS daemon to crash, orpotentially execute arbitrary code. Please note that the default CUPSconfiguration does not allow remote hosts to connect to the IPP TCP port.(CVE-2007-4351)In addition, the following bugs were fixed:* the CUPS service has been changed to start after sshd, to avoid causingdelays when logging in when the system is booted.* the logrotate settings have been adjusted so they do not cause CUPS toreload its configuration. This is to avoid re-printing the current job,which could occur when it was a long-running job.* a bug has been fixed in the handling of the If-Modified-Since: HTTPheader.* in the LSPP configuration, labels for labeled jobs did not line-wrap.This has been fixed.* an access check in the LSPP configuration has been made more secure.* the cups-lpd service no longer ignores the "-odocument-format=..."option.* a memory allocation bug has been fixed in cupsd.* support for UNIX domain sockets authentication without passwords has beenadded.* in the LSPP configuration, a problem that could lead to cupsd crashinghas been fixed.* the error handling in the initscript has been improved.* The job-originating-host-name attribute was not correctly set for jobssubmitted via the cups-lpd service. This has been fixed.* a problem with parsing IPv6 addresses in the configuration file has beenfixed.* a problem that could lead to cupsd crashing when it failed to open a"file:" URI has been fixed.SL 5.x SRPMS:cups-1.2.4-11.14.el5.1.src.rpm i386:cups-1.2.4-11.14.el5.1.i386.rpmcups-devel-1.2.4-11.14.el5.1.i386.rpmcups-libs-1.2.4-11.14.el5.1.i386.rpmcups-lpd-1.2.4-11.14.el5.1.i386.rpm x86_64:cups-1.2.4-11.14.el5.1.x86_64.rpmcups-devel-1.2.4-11.14.el5.1.i386.rpmcups-devel-1.2.4-11.14.el5.1.x86_64.rpmcups-libs-1.2.4-11.14.el5.1.i386.rpmcups-libs-1.2.4-11.14.el5.1.x86_64.rpmcups-lpd-1.2.4-11.14.el5.1.x86_64.rpm-Connie Sieh-Troy Dawson