Security Advisory Important: cups security update

Advisory: RHSA-2009:0308-4
Type: Security Advisory
Severity: Important
Issued on: 2009-02-19
Last updated on: 2009-02-19
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
OVAL: com.redhat.rhsa-20090308.xml
CVEs (cve.mitre.org): CVE-2009-0577

Details

Updated cups packages that fix a security issue are now available for Red
Hat Enterprise Linux 3.

This update has been rated as having important security impact by the Red
Hat Security Response Team.

The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

The CUPS security advisory, RHSA-2008:0937, stated that it fixed
CVE-2008-3640 for Red Hat Enterprise Linux 3, 4, and 5. It was discovered
this flaw was not properly fixed on Red Hat Enterprise Linux 3, however.
(CVE-2009-0577)

These new packages contain a proper fix for CVE-2008-3640 on Red Hat
Enterprise Linux 3. Red Hat Enterprise Linux 4 and 5 already contain the
appropriate fix for this flaw and do not need to be updated.

Users of cups should upgrade to these updated packages, which contain a
backported patch to correct this issue.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
cups-1.1.17-13.3.56.src.rpm
File outdated by:  RHSA-2009:1083
    8739c03fdd9f3c542b3c51d40d5b0517
 
IA-32:
cups-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    6f56a075a6d9288bdd6d6030e96016f8
cups-devel-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    c833457d19ca6957c30dc32ff499b659
cups-libs-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    34435e68c708d839caf349d4ab39a81b
 
x86_64:
cups-1.1.17-13.3.56.x86_64.rpm
File outdated by:  RHSA-2009:1083
    ed56595ca242e3233e1ec0a4a61bfdaa
cups-devel-1.1.17-13.3.56.x86_64.rpm
File outdated by:  RHSA-2009:1083
    349a0f2347fb5166226fe59b0b282745
cups-libs-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    34435e68c708d839caf349d4ab39a81b
cups-libs-1.1.17-13.3.56.x86_64.rpm
File outdated by:  RHSA-2009:1083
    ac2a0c0a55d0d1a6dad76f3b6df4ce99
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
cups-1.1.17-13.3.56.src.rpm
File outdated by:  RHSA-2009:1083
    8739c03fdd9f3c542b3c51d40d5b0517
 
IA-32:
cups-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    6f56a075a6d9288bdd6d6030e96016f8
cups-devel-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    c833457d19ca6957c30dc32ff499b659
cups-libs-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    34435e68c708d839caf349d4ab39a81b
 
IA-64:
cups-1.1.17-13.3.56.ia64.rpm
File outdated by:  RHSA-2009:1083
    32368d0229e6481a03c94a3a1c86de92
cups-devel-1.1.17-13.3.56.ia64.rpm
File outdated by:  RHSA-2009:1083
    63bfdcefa0c7a9713e0b23270d816833
cups-libs-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    34435e68c708d839caf349d4ab39a81b
cups-libs-1.1.17-13.3.56.ia64.rpm
File outdated by:  RHSA-2009:1083
    fef08a8baf661e64c2d5c15855cf78a4
 
PPC:
cups-1.1.17-13.3.56.ppc.rpm
File outdated by:  RHSA-2009:1083
    7a68a48fbcdbae45709784a56f57ffcb
cups-devel-1.1.17-13.3.56.ppc.rpm
File outdated by:  RHSA-2009:1083
    a5fb56f38dae3360ffbb05aee90ef3ec
cups-libs-1.1.17-13.3.56.ppc.rpm
File outdated by:  RHSA-2009:1083
    528426d740d93e3d5e788df3c4b8229e
cups-libs-1.1.17-13.3.56.ppc64.rpm
File outdated by:  RHSA-2009:1083
    0b51a9810202d4dce6a58c1cb93055ed
 
s390:
cups-1.1.17-13.3.56.s390.rpm
File outdated by:  RHSA-2009:1083
    120dfff8ec5acf01a45c0dd6834fe029
cups-devel-1.1.17-13.3.56.s390.rpm
File outdated by:  RHSA-2009:1083
    4d9cea9fd3b6e2947ac8fc71001f6853
cups-libs-1.1.17-13.3.56.s390.rpm
File outdated by:  RHSA-2009:1083
    eccc091edb9ff261892219f51b39f3c8
 
s390x:
cups-1.1.17-13.3.56.s390x.rpm
File outdated by:  RHSA-2009:1083
    8395236a084989ee8ebd873eebad09f5
cups-devel-1.1.17-13.3.56.s390x.rpm
File outdated by:  RHSA-2009:1083
    08c5877d4f9ee4a792936fc73e83ef5b
cups-libs-1.1.17-13.3.56.s390.rpm
File outdated by:  RHSA-2009:1083
    eccc091edb9ff261892219f51b39f3c8
cups-libs-1.1.17-13.3.56.s390x.rpm
File outdated by:  RHSA-2009:1083
    c5e5b8200f08a69150e7f4d20123902c
 
x86_64:
cups-1.1.17-13.3.56.x86_64.rpm
File outdated by:  RHSA-2009:1083
    ed56595ca242e3233e1ec0a4a61bfdaa
cups-devel-1.1.17-13.3.56.x86_64.rpm
File outdated by:  RHSA-2009:1083
    349a0f2347fb5166226fe59b0b282745
cups-libs-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    34435e68c708d839caf349d4ab39a81b
cups-libs-1.1.17-13.3.56.x86_64.rpm
File outdated by:  RHSA-2009:1083
    ac2a0c0a55d0d1a6dad76f3b6df4ce99
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
cups-1.1.17-13.3.56.src.rpm
File outdated by:  RHSA-2009:1083
    8739c03fdd9f3c542b3c51d40d5b0517
 
IA-32:
cups-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    6f56a075a6d9288bdd6d6030e96016f8
cups-devel-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    c833457d19ca6957c30dc32ff499b659
cups-libs-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    34435e68c708d839caf349d4ab39a81b
 
IA-64:
cups-1.1.17-13.3.56.ia64.rpm
File outdated by:  RHSA-2009:1083
    32368d0229e6481a03c94a3a1c86de92
cups-devel-1.1.17-13.3.56.ia64.rpm
File outdated by:  RHSA-2009:1083
    63bfdcefa0c7a9713e0b23270d816833
cups-libs-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    34435e68c708d839caf349d4ab39a81b
cups-libs-1.1.17-13.3.56.ia64.rpm
File outdated by:  RHSA-2009:1083
    fef08a8baf661e64c2d5c15855cf78a4
 
x86_64:
cups-1.1.17-13.3.56.x86_64.rpm
File outdated by:  RHSA-2009:1083
    ed56595ca242e3233e1ec0a4a61bfdaa
cups-devel-1.1.17-13.3.56.x86_64.rpm
File outdated by:  RHSA-2009:1083
    349a0f2347fb5166226fe59b0b282745
cups-libs-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    34435e68c708d839caf349d4ab39a81b
cups-libs-1.1.17-13.3.56.x86_64.rpm
File outdated by:  RHSA-2009:1083
    ac2a0c0a55d0d1a6dad76f3b6df4ce99
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
cups-1.1.17-13.3.56.src.rpm
File outdated by:  RHSA-2009:1083
    8739c03fdd9f3c542b3c51d40d5b0517
 
IA-32:
cups-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    6f56a075a6d9288bdd6d6030e96016f8
cups-devel-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    c833457d19ca6957c30dc32ff499b659
cups-libs-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    34435e68c708d839caf349d4ab39a81b
 
IA-64:
cups-1.1.17-13.3.56.ia64.rpm
File outdated by:  RHSA-2009:1083
    32368d0229e6481a03c94a3a1c86de92
cups-devel-1.1.17-13.3.56.ia64.rpm
File outdated by:  RHSA-2009:1083
    63bfdcefa0c7a9713e0b23270d816833
cups-libs-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    34435e68c708d839caf349d4ab39a81b
cups-libs-1.1.17-13.3.56.ia64.rpm
File outdated by:  RHSA-2009:1083
    fef08a8baf661e64c2d5c15855cf78a4
 
x86_64:
cups-1.1.17-13.3.56.x86_64.rpm
File outdated by:  RHSA-2009:1083
    ed56595ca242e3233e1ec0a4a61bfdaa
cups-devel-1.1.17-13.3.56.x86_64.rpm
File outdated by:  RHSA-2009:1083
    349a0f2347fb5166226fe59b0b282745
cups-libs-1.1.17-13.3.56.i386.rpm
File outdated by:  RHSA-2009:1083
    34435e68c708d839caf349d4ab39a81b
cups-libs-1.1.17-13.3.56.x86_64.rpm
File outdated by:  RHSA-2009:1083
    ac2a0c0a55d0d1a6dad76f3b6df4ce99
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

486052 - CVE-2009-0577 cups-CVE-2008-3640.patch has been corrupted.


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/