[slackware-security] CUPS DoS vulnerability fixed (SSA:2003-149-01)

From: Slackware Security Team (security_at_slackware.com)
Date: 05/29/03

  • Next message: pokleyzz: "Geeklog 1.3.7sr1 and below multiple vulnerabilities."
    Date: Thu, 29 May 2003 02:26:18 -0700 (PDT)
    To: slackware-security@slackware.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    [slackware-security] CUPS DoS vulnerability fixed (SSA:2003-149-01)

    Upgraded CUPS packages are available for Slackware 8.1, 9.0,
    and -current to fix a denial of service attack vulnerability.

    Here are the details from the Slackware 9.0 ChangeLog:
    +--------------------------+
    Thu May 29 00:52:54 PDT 2003
    patches/packages/cups-1.1.19-i386-1.tgz: Upgraded to cups-1.1.19.
      A denial of service problem that allowed a CUPS client to hang the CUPS
      server is now fixed in CUPS 1.1.19. Note that CUPS is not installed by
      default -- it is shipped as one of the packages in /extra.
      (* Security fix *)
    +--------------------------+

    WHERE TO FIND THE NEW PACKAGES:
    +-----------------------------+

    Updated package for Slackware 8.1:
    ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/cups-1.1.19-i386-1.tgz

    Updated package for Slackware 9.0:
    ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/cups-1.1.19-i386-1.tgz

    Updated package for Slackware -current:
    ftp://ftp.slackware.com/pub/slackware/slackware-current/extra/cups-1.1.19/cups-1.1.19-i486-1.tgz

    MD5 SIGNATURES:
    +-------------+

    Slackware 8.1 package:
    c8999b9d8ec4652372d2ef5f26a1c71b cups-1.1.19-i386-1.tgz

    Slackware 9.0 package:
    72bd865d7b3ff4695340522e1c86ae9c cups-1.1.19-i386-1.tgz

    Slackware -current package:
    7d5aa6d2408b642f2db46ac8387ada2b cups-1.1.19-i486-1.tgz

    INSTALLATION INSTRUCTIONS:
    +------------------------+

    First, if the CUPS server (cupsd) is running, stop it:
    . /etc/rc.d/rc.cups stop

    Then upgrade using upgradepkg (as root):
    upgradepkg cups-1.1.19-i386-1.tgz

    Finally, restart cupsd (if needed):
    . /etc/rc.d/rc.cups start

    +-----+

    Slackware Linux Security Team
    http://slackware.com/gpg-key
    security@slackware.com

    +------------------------------------------------------------------------+
    | HOW TO REMOVE YOURSELF FROM THIS MAILING LIST: |
    +------------------------------------------------------------------------+
    | Send an email to majordomo@slackware.com with this text in the body of |
    | the email message: |
    | |
    | unsubscribe slackware-security |
    | |
    | You will get a confirmation message back. Follow the instructions to |
    | complete the unsubscription. Do not reply to this message to |
    | unsubscribe! |
    +------------------------------------------------------------------------+

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.2 (GNU/Linux)

    iD8DBQE+1cBuakRjwEAQIjMRAtunAJ4t/awb0KZPl4OXgs2ObLCriSGYBQCfQ6zW
    0NHuoLNJPXWcu7m6InfcFqU=
    =hhxK
    -----END PGP SIGNATURE-----


  • Next message: pokleyzz: "Geeklog 1.3.7sr1 and below multiple vulnerabilities."

    Relevant Pages

    • [slackware-security] WU-FTPD Security Advisory (SSA:2003-259-03)
      ... Here are the details from the Slackware 9.0 ChangeLog: ... (* Security fix *) ... Updated package for Slackware -current: ... Upgrade using upgradepkg: ...
      (Bugtraq)
    • Re: machine
      ... You can use Slackware's package management system, ... installpkg - Install a Slackware package ... You can compile the program from the source. ... > install something, something else had to get uninstalled, ...
      (alt.os.linux)
    • [slackware-security] nfs-utils packages replaced (SSA:2003-195-01b)
      ... in utils/mountd/auth.c that could cause mountd to crash. ... Here are the details from the Slackware 9.0 ChangeLog: ... Updated package for Slackware 8.1: ... Then upgrade using upgradepkg: ...
      (Bugtraq)
    • [slackware-security] GDM security update (SSA:2003-236-01)
      ... Upgraded gdm packages are available for Slackware 9.0 and -current. ... These fix a security issue where a local user may use GDM to read any ... Updated package for Slackware -current: ... Upgrade using upgradepkg: ...
      (Bugtraq)
    • [slackware-security] metamail security update (SSA:2004-049-02)
      ... Metamail is a set of utilities for processing MIME mail. ... overflows which could lead to unauthorized code execution. ... Here are the details from the Slackware 9.1 ChangeLog: ... WHERE TO FIND THE NEW PACKAGE: ...
      (Bugtraq)