Security Advisory Moderate: cups security update

Advisory: RHSA-2008:1028-7
Type: Security Advisory
Severity: Moderate
Issued on: 2008-12-15
Last updated on: 2008-12-15
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
OVAL: com.redhat.rhsa-20081028.xml
CVEs (cve.mitre.org): CVE-2008-5286

Details

Updated cups packages that fix a security issue are now available for Red
Hat Enterprise Linux 3.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

An integer overflow flaw, leading to a heap buffer overflow, was discovered
in the Portable Network Graphics (PNG) decoding routines used by the CUPS
image-converting filters, "imagetops" and "imagetoraster". An attacker
could create a malicious PNG file that could, potentially, execute
arbitrary code as the "lp" user if the file was printed. (CVE-2008-5286)

CUPS users should upgrade to these updated packages, which contain a
backported patch to correct this issue.


Solution

Before applying this update, make sure that all previously-released errata
relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use the Red
Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
cups-1.1.17-13.3.55.src.rpm
File outdated by:  RHSA-2009:1083
    6157f19d12f550ebb33020192cfeb8d8
 
IA-32:
cups-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    af0fd4849f985234e2a95ec2b84457df
cups-devel-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    4ab3528fe62cbd8f2f2cd0ba9106279c
cups-libs-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    fc9d3730315a1c58322424001eef4680
 
x86_64:
cups-1.1.17-13.3.55.x86_64.rpm
File outdated by:  RHSA-2009:1083
    6033bd3318a6bedb8575461794c15aa2
cups-devel-1.1.17-13.3.55.x86_64.rpm
File outdated by:  RHSA-2009:1083
    4918eff8909e0dfa95a6f9af6e8941f1
cups-libs-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    fc9d3730315a1c58322424001eef4680
cups-libs-1.1.17-13.3.55.x86_64.rpm
File outdated by:  RHSA-2009:1083
    69d0d8b146739a1db2a2819f41b7e404
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
cups-1.1.17-13.3.55.src.rpm
File outdated by:  RHSA-2009:1083
    6157f19d12f550ebb33020192cfeb8d8
 
IA-32:
cups-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    af0fd4849f985234e2a95ec2b84457df
cups-devel-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    4ab3528fe62cbd8f2f2cd0ba9106279c
cups-libs-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    fc9d3730315a1c58322424001eef4680
 
IA-64:
cups-1.1.17-13.3.55.ia64.rpm
File outdated by:  RHSA-2009:1083
    002993629ae495e5fde9f9d838f8f772
cups-devel-1.1.17-13.3.55.ia64.rpm
File outdated by:  RHSA-2009:1083
    91f35107083048b9b61f8f1e289f1dd3
cups-libs-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    fc9d3730315a1c58322424001eef4680
cups-libs-1.1.17-13.3.55.ia64.rpm
File outdated by:  RHSA-2009:1083
    49721b4649277155dd0e9a83876fc075
 
PPC:
cups-1.1.17-13.3.55.ppc.rpm
File outdated by:  RHSA-2009:1083
    40603b57dcec37c0479ebfd253b15f4a
cups-devel-1.1.17-13.3.55.ppc.rpm
File outdated by:  RHSA-2009:1083
    bfad86a5265a4048a43aadda4c7a83a9
cups-libs-1.1.17-13.3.55.ppc.rpm
File outdated by:  RHSA-2009:1083
    3ca4d1f184abbd16a326c28b8442620b
cups-libs-1.1.17-13.3.55.ppc64.rpm
File outdated by:  RHSA-2009:1083
    7aedda7e653555eb6a599962dd1fa003
 
s390:
cups-1.1.17-13.3.55.s390.rpm
File outdated by:  RHSA-2009:1083
    9f372c0fcf5709f15a76e812109e7110
cups-devel-1.1.17-13.3.55.s390.rpm
File outdated by:  RHSA-2009:1083
    2061c57bc24bf354a0d1dc2c71913e08
cups-libs-1.1.17-13.3.55.s390.rpm
File outdated by:  RHSA-2009:1083
    e9c0d7ed9c7a2a8e0bba0b6842e52ab7
 
s390x:
cups-1.1.17-13.3.55.s390x.rpm
File outdated by:  RHSA-2009:1083
    589c99c36d73898dfad88aaa3dbdeff1
cups-devel-1.1.17-13.3.55.s390x.rpm
File outdated by:  RHSA-2009:1083
    6b55ba3a255a967359a73cc19c913cfb
cups-libs-1.1.17-13.3.55.s390.rpm
File outdated by:  RHSA-2009:1083
    e9c0d7ed9c7a2a8e0bba0b6842e52ab7
cups-libs-1.1.17-13.3.55.s390x.rpm
File outdated by:  RHSA-2009:1083
    d4e2ece1a10da8b462bdbabf69ec2489
 
x86_64:
cups-1.1.17-13.3.55.x86_64.rpm
File outdated by:  RHSA-2009:1083
    6033bd3318a6bedb8575461794c15aa2
cups-devel-1.1.17-13.3.55.x86_64.rpm
File outdated by:  RHSA-2009:1083
    4918eff8909e0dfa95a6f9af6e8941f1
cups-libs-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    fc9d3730315a1c58322424001eef4680
cups-libs-1.1.17-13.3.55.x86_64.rpm
File outdated by:  RHSA-2009:1083
    69d0d8b146739a1db2a2819f41b7e404
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
cups-1.1.17-13.3.55.src.rpm
File outdated by:  RHSA-2009:1083
    6157f19d12f550ebb33020192cfeb8d8
 
IA-32:
cups-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    af0fd4849f985234e2a95ec2b84457df
cups-devel-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    4ab3528fe62cbd8f2f2cd0ba9106279c
cups-libs-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    fc9d3730315a1c58322424001eef4680
 
IA-64:
cups-1.1.17-13.3.55.ia64.rpm
File outdated by:  RHSA-2009:1083
    002993629ae495e5fde9f9d838f8f772
cups-devel-1.1.17-13.3.55.ia64.rpm
File outdated by:  RHSA-2009:1083
    91f35107083048b9b61f8f1e289f1dd3
cups-libs-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    fc9d3730315a1c58322424001eef4680
cups-libs-1.1.17-13.3.55.ia64.rpm
File outdated by:  RHSA-2009:1083
    49721b4649277155dd0e9a83876fc075
 
x86_64:
cups-1.1.17-13.3.55.x86_64.rpm
File outdated by:  RHSA-2009:1083
    6033bd3318a6bedb8575461794c15aa2
cups-devel-1.1.17-13.3.55.x86_64.rpm
File outdated by:  RHSA-2009:1083
    4918eff8909e0dfa95a6f9af6e8941f1
cups-libs-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    fc9d3730315a1c58322424001eef4680
cups-libs-1.1.17-13.3.55.x86_64.rpm
File outdated by:  RHSA-2009:1083
    69d0d8b146739a1db2a2819f41b7e404
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
cups-1.1.17-13.3.55.src.rpm
File outdated by:  RHSA-2009:1083
    6157f19d12f550ebb33020192cfeb8d8
 
IA-32:
cups-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    af0fd4849f985234e2a95ec2b84457df
cups-devel-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    4ab3528fe62cbd8f2f2cd0ba9106279c
cups-libs-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    fc9d3730315a1c58322424001eef4680
 
IA-64:
cups-1.1.17-13.3.55.ia64.rpm
File outdated by:  RHSA-2009:1083
    002993629ae495e5fde9f9d838f8f772
cups-devel-1.1.17-13.3.55.ia64.rpm
File outdated by:  RHSA-2009:1083
    91f35107083048b9b61f8f1e289f1dd3
cups-libs-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    fc9d3730315a1c58322424001eef4680
cups-libs-1.1.17-13.3.55.ia64.rpm
File outdated by:  RHSA-2009:1083
    49721b4649277155dd0e9a83876fc075
 
x86_64:
cups-1.1.17-13.3.55.x86_64.rpm
File outdated by:  RHSA-2009:1083
    6033bd3318a6bedb8575461794c15aa2
cups-devel-1.1.17-13.3.55.x86_64.rpm
File outdated by:  RHSA-2009:1083
    4918eff8909e0dfa95a6f9af6e8941f1
cups-libs-1.1.17-13.3.55.i386.rpm
File outdated by:  RHSA-2009:1083
    fc9d3730315a1c58322424001eef4680
cups-libs-1.1.17-13.3.55.x86_64.rpm
File outdated by:  RHSA-2009:1083
    69d0d8b146739a1db2a2819f41b7e404
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

473905 - CVE-2008-5286 cups: Incomplete fix for CVE-2008-1722


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/