Skip to navigation

Security Advisory Important: cups security update

Advisory: RHSA-2010:0754-1
Type: Security Advisory
Severity: Important
Issued on: 2010-10-07
Last updated on: 2010-10-07
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
CVEs (cve.mitre.org): CVE-2010-3702

Details

Updated cups packages that fix one security issue are now available for Red
Hat Enterprise Linux 3.

The Red Hat Security Response Team has rated this update as having
important security impact. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available from the
CVE link in the References section.

The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX operating systems. The CUPS "pdftops" filter converts Portable
Document Format (PDF) files to PostScript.

An uninitialized pointer use flaw was discovered in the CUPS "pdftops"
filter. An attacker could create a malicious PDF file that, when printed,
would cause "pdftops" to crash or, potentially, execute arbitrary code as
the "lp" user. (CVE-2010-3702)

Users of cups are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the cupsd daemon will be restarted automatically.


Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/SRPMS/cups-1.1.17-13.3.70.src.rpm
Missing file
    MD5: cf820e368bc2a05116734297184486dc
SHA-256: 090afa748a6986e37391fc16e85ba9e66b6bb6ccc69c891bd09eceffd43eadfa
 
IA-32:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/i386/cups-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: 69af9360a7310366be6f6104942a9951
SHA-256: 6bc0849f3e7c6359c2d7e9b8820e022dcc9e426706b348de1eec02949445c34c
ftp://updates.redhat.com/rhn/public/NULL/cups-devel/1.1.17-13.3.70/i386/cups-devel-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: 84702c74075b96c20c1e264b9da04ecc
SHA-256: ab8ac91299afcdc9b9dbf12ffa0215641e39bad695ce7d8b6bc35f09026aa0d1
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/i386/cups-libs-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: a6d1f73c7d64bde200089bd2a0c2de36
SHA-256: 6cfe44b4d6432f6dae4ae2939d75549bf6cf18151fd06c51319ed543c8f2da8a
 
x86_64:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/x86_64/cups-1.1.17-13.3.70.x86_64.rpm
Missing file
    MD5: 6aa1d305e5423bd3f0e3ce9b65753648
SHA-256: 941cad556a46365fc13e1601bfb7c1b217f787c1dcb4057da71de6f89fd68970
ftp://updates.redhat.com/rhn/public/NULL/cups-devel/1.1.17-13.3.70/x86_64/cups-devel-1.1.17-13.3.70.x86_64.rpm
Missing file
    MD5: a286d93802549bb91b302222718a0703
SHA-256: 58dccb14ca5d7d7334da3b81006f8f95cfd173840fa9466213f7ee948c9a0517
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/i386/cups-libs-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: a6d1f73c7d64bde200089bd2a0c2de36
SHA-256: 6cfe44b4d6432f6dae4ae2939d75549bf6cf18151fd06c51319ed543c8f2da8a
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/x86_64/cups-libs-1.1.17-13.3.70.x86_64.rpm
Missing file
    MD5: e4330a0505f064a1e9a709d45d8a6fdc
SHA-256: 286e646e2812e7ce803c852a78671448c20586ac7660b6f53f70bddc3c87c374
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/SRPMS/cups-1.1.17-13.3.70.src.rpm
Missing file
    MD5: cf820e368bc2a05116734297184486dc
SHA-256: 090afa748a6986e37391fc16e85ba9e66b6bb6ccc69c891bd09eceffd43eadfa
 
IA-32:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/i386/cups-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: 69af9360a7310366be6f6104942a9951
SHA-256: 6bc0849f3e7c6359c2d7e9b8820e022dcc9e426706b348de1eec02949445c34c
ftp://updates.redhat.com/rhn/public/NULL/cups-devel/1.1.17-13.3.70/i386/cups-devel-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: 84702c74075b96c20c1e264b9da04ecc
SHA-256: ab8ac91299afcdc9b9dbf12ffa0215641e39bad695ce7d8b6bc35f09026aa0d1
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/i386/cups-libs-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: a6d1f73c7d64bde200089bd2a0c2de36
SHA-256: 6cfe44b4d6432f6dae4ae2939d75549bf6cf18151fd06c51319ed543c8f2da8a
 
IA-64:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/ia64/cups-1.1.17-13.3.70.ia64.rpm
Missing file
    MD5: c1499ec1d0519207a99a77241bab73e9
SHA-256: df36594f0328383ccf481026ba7a25d579b1b9334d3650da1aa26c44f4100602
ftp://updates.redhat.com/rhn/public/NULL/cups-devel/1.1.17-13.3.70/ia64/cups-devel-1.1.17-13.3.70.ia64.rpm
Missing file
    MD5: 8b736eb9896fdd74f30a2006fd27abc0
SHA-256: a6732e66d46b16af0a8072ffc449c42f1174b1e92996474200b091567c21d436
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/i386/cups-libs-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: a6d1f73c7d64bde200089bd2a0c2de36
SHA-256: 6cfe44b4d6432f6dae4ae2939d75549bf6cf18151fd06c51319ed543c8f2da8a
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/ia64/cups-libs-1.1.17-13.3.70.ia64.rpm
Missing file
    MD5: de89297b8ac1ddf3c467be50b85c4de4
SHA-256: 60cde48d0cb24b0f9b67e0d8403b9595e5a85798b6b18a969fdbbf06767372ca
 
PPC:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/ppc/cups-1.1.17-13.3.70.ppc.rpm
Missing file
    MD5: 21ce00d9825d58697d754dca8efd36cb
SHA-256: 0de17091db9aaafbee8583b54326c09de4297c5afda1a44f3923bc8eed4717bb
ftp://updates.redhat.com/rhn/public/NULL/cups-devel/1.1.17-13.3.70/ppc/cups-devel-1.1.17-13.3.70.ppc.rpm
Missing file
    MD5: 779b105555fc0cda871860920fa0b1c2
SHA-256: 4a7b0f484bfe88b0a0d4e1527bb9fc6b3316f54f41964b64f56ccf2d8f28e792
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/ppc/cups-libs-1.1.17-13.3.70.ppc.rpm
Missing file
    MD5: bdf6eb1d4a1f33418c79c452b488e0a4
SHA-256: 653757b9abd7a4527f6db908a98a38ef142ec46fe625e9fcc9b8ddf655deb455
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/ppc64/cups-libs-1.1.17-13.3.70.ppc64.rpm
Missing file
    MD5: 528a3247e79c5fd0e70ecf8d4c7a8357
SHA-256: 36a407fdfeac679d37443511eb3a23cf76ca9cbff332ee5465f727962e9127ac
 
s390:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/s390/cups-1.1.17-13.3.70.s390.rpm
Missing file
    MD5: 5cae5a35a85ed281171f72d03acb5ef8
SHA-256: f21bf244a5ad0e342099557c315fd6f6118f1469d344772217fb0737f537f774
ftp://updates.redhat.com/rhn/public/NULL/cups-devel/1.1.17-13.3.70/s390/cups-devel-1.1.17-13.3.70.s390.rpm
Missing file
    MD5: 4fe5cfa1460cb75ea480b56712a98cf9
SHA-256: c3fbb994135605bec3e43034bd1fb03ba86ab1d3102a1cc0eb0f1c1d912ae39f
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/s390/cups-libs-1.1.17-13.3.70.s390.rpm
Missing file
    MD5: 086db825fa930aad29fbec7385d49699
SHA-256: 124a027b41dbc9145e78a3395aea08bfa6ee9d43188c55d45f077a91bb3aad1f
 
s390x:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/s390x/cups-1.1.17-13.3.70.s390x.rpm
Missing file
    MD5: 664ed2e34cfd32b2cb119e760a792057
SHA-256: 2eaea139cfedb4c25b3ea3ad92403f6dc84fcfd97383a22acf2ba4dc36e1966e
ftp://updates.redhat.com/rhn/public/NULL/cups-devel/1.1.17-13.3.70/s390x/cups-devel-1.1.17-13.3.70.s390x.rpm
Missing file
    MD5: c95516c9586b0479a99d392c83d7672b
SHA-256: 0131d88dbad06a1519d41e931af9aad62150dc6e5032b8090b5f64e1376d7786
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/s390/cups-libs-1.1.17-13.3.70.s390.rpm
Missing file
    MD5: 086db825fa930aad29fbec7385d49699
SHA-256: 124a027b41dbc9145e78a3395aea08bfa6ee9d43188c55d45f077a91bb3aad1f
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/s390x/cups-libs-1.1.17-13.3.70.s390x.rpm
Missing file
    MD5: bf134113029883c8d9cd439751494395
SHA-256: cafbf73fc01b70481f58bcbca9b6a9d548df05ec91418187572dbb9615f043ba
 
x86_64:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/x86_64/cups-1.1.17-13.3.70.x86_64.rpm
Missing file
    MD5: 6aa1d305e5423bd3f0e3ce9b65753648
SHA-256: 941cad556a46365fc13e1601bfb7c1b217f787c1dcb4057da71de6f89fd68970
ftp://updates.redhat.com/rhn/public/NULL/cups-devel/1.1.17-13.3.70/x86_64/cups-devel-1.1.17-13.3.70.x86_64.rpm
Missing file
    MD5: a286d93802549bb91b302222718a0703
SHA-256: 58dccb14ca5d7d7334da3b81006f8f95cfd173840fa9466213f7ee948c9a0517
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/i386/cups-libs-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: a6d1f73c7d64bde200089bd2a0c2de36
SHA-256: 6cfe44b4d6432f6dae4ae2939d75549bf6cf18151fd06c51319ed543c8f2da8a
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/x86_64/cups-libs-1.1.17-13.3.70.x86_64.rpm
Missing file
    MD5: e4330a0505f064a1e9a709d45d8a6fdc
SHA-256: 286e646e2812e7ce803c852a78671448c20586ac7660b6f53f70bddc3c87c374
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/SRPMS/cups-1.1.17-13.3.70.src.rpm
Missing file
    MD5: cf820e368bc2a05116734297184486dc
SHA-256: 090afa748a6986e37391fc16e85ba9e66b6bb6ccc69c891bd09eceffd43eadfa
 
IA-32:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/i386/cups-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: 69af9360a7310366be6f6104942a9951
SHA-256: 6bc0849f3e7c6359c2d7e9b8820e022dcc9e426706b348de1eec02949445c34c
ftp://updates.redhat.com/rhn/public/NULL/cups-devel/1.1.17-13.3.70/i386/cups-devel-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: 84702c74075b96c20c1e264b9da04ecc
SHA-256: ab8ac91299afcdc9b9dbf12ffa0215641e39bad695ce7d8b6bc35f09026aa0d1
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/i386/cups-libs-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: a6d1f73c7d64bde200089bd2a0c2de36
SHA-256: 6cfe44b4d6432f6dae4ae2939d75549bf6cf18151fd06c51319ed543c8f2da8a
 
IA-64:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/ia64/cups-1.1.17-13.3.70.ia64.rpm
Missing file
    MD5: c1499ec1d0519207a99a77241bab73e9
SHA-256: df36594f0328383ccf481026ba7a25d579b1b9334d3650da1aa26c44f4100602
ftp://updates.redhat.com/rhn/public/NULL/cups-devel/1.1.17-13.3.70/ia64/cups-devel-1.1.17-13.3.70.ia64.rpm
Missing file
    MD5: 8b736eb9896fdd74f30a2006fd27abc0
SHA-256: a6732e66d46b16af0a8072ffc449c42f1174b1e92996474200b091567c21d436
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/i386/cups-libs-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: a6d1f73c7d64bde200089bd2a0c2de36
SHA-256: 6cfe44b4d6432f6dae4ae2939d75549bf6cf18151fd06c51319ed543c8f2da8a
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/ia64/cups-libs-1.1.17-13.3.70.ia64.rpm
Missing file
    MD5: de89297b8ac1ddf3c467be50b85c4de4
SHA-256: 60cde48d0cb24b0f9b67e0d8403b9595e5a85798b6b18a969fdbbf06767372ca
 
x86_64:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/x86_64/cups-1.1.17-13.3.70.x86_64.rpm
Missing file
    MD5: 6aa1d305e5423bd3f0e3ce9b65753648
SHA-256: 941cad556a46365fc13e1601bfb7c1b217f787c1dcb4057da71de6f89fd68970
ftp://updates.redhat.com/rhn/public/NULL/cups-devel/1.1.17-13.3.70/x86_64/cups-devel-1.1.17-13.3.70.x86_64.rpm
Missing file
    MD5: a286d93802549bb91b302222718a0703
SHA-256: 58dccb14ca5d7d7334da3b81006f8f95cfd173840fa9466213f7ee948c9a0517
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/i386/cups-libs-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: a6d1f73c7d64bde200089bd2a0c2de36
SHA-256: 6cfe44b4d6432f6dae4ae2939d75549bf6cf18151fd06c51319ed543c8f2da8a
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/x86_64/cups-libs-1.1.17-13.3.70.x86_64.rpm
Missing file
    MD5: e4330a0505f064a1e9a709d45d8a6fdc
SHA-256: 286e646e2812e7ce803c852a78671448c20586ac7660b6f53f70bddc3c87c374
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/SRPMS/cups-1.1.17-13.3.70.src.rpm
Missing file
    MD5: cf820e368bc2a05116734297184486dc
SHA-256: 090afa748a6986e37391fc16e85ba9e66b6bb6ccc69c891bd09eceffd43eadfa
 
IA-32:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/i386/cups-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: 69af9360a7310366be6f6104942a9951
SHA-256: 6bc0849f3e7c6359c2d7e9b8820e022dcc9e426706b348de1eec02949445c34c
ftp://updates.redhat.com/rhn/public/NULL/cups-devel/1.1.17-13.3.70/i386/cups-devel-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: 84702c74075b96c20c1e264b9da04ecc
SHA-256: ab8ac91299afcdc9b9dbf12ffa0215641e39bad695ce7d8b6bc35f09026aa0d1
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/i386/cups-libs-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: a6d1f73c7d64bde200089bd2a0c2de36
SHA-256: 6cfe44b4d6432f6dae4ae2939d75549bf6cf18151fd06c51319ed543c8f2da8a
 
IA-64:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/ia64/cups-1.1.17-13.3.70.ia64.rpm
Missing file
    MD5: c1499ec1d0519207a99a77241bab73e9
SHA-256: df36594f0328383ccf481026ba7a25d579b1b9334d3650da1aa26c44f4100602
ftp://updates.redhat.com/rhn/public/NULL/cups-devel/1.1.17-13.3.70/ia64/cups-devel-1.1.17-13.3.70.ia64.rpm
Missing file
    MD5: 8b736eb9896fdd74f30a2006fd27abc0
SHA-256: a6732e66d46b16af0a8072ffc449c42f1174b1e92996474200b091567c21d436
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/i386/cups-libs-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: a6d1f73c7d64bde200089bd2a0c2de36
SHA-256: 6cfe44b4d6432f6dae4ae2939d75549bf6cf18151fd06c51319ed543c8f2da8a
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/ia64/cups-libs-1.1.17-13.3.70.ia64.rpm
Missing file
    MD5: de89297b8ac1ddf3c467be50b85c4de4
SHA-256: 60cde48d0cb24b0f9b67e0d8403b9595e5a85798b6b18a969fdbbf06767372ca
 
x86_64:
ftp://updates.redhat.com/rhn/public/NULL/cups/1.1.17-13.3.70/x86_64/cups-1.1.17-13.3.70.x86_64.rpm
Missing file
    MD5: 6aa1d305e5423bd3f0e3ce9b65753648
SHA-256: 941cad556a46365fc13e1601bfb7c1b217f787c1dcb4057da71de6f89fd68970
ftp://updates.redhat.com/rhn/public/NULL/cups-devel/1.1.17-13.3.70/x86_64/cups-devel-1.1.17-13.3.70.x86_64.rpm
Missing file
    MD5: a286d93802549bb91b302222718a0703
SHA-256: 58dccb14ca5d7d7334da3b81006f8f95cfd173840fa9466213f7ee948c9a0517
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/i386/cups-libs-1.1.17-13.3.70.i386.rpm
Missing file
    MD5: a6d1f73c7d64bde200089bd2a0c2de36
SHA-256: 6cfe44b4d6432f6dae4ae2939d75549bf6cf18151fd06c51319ed543c8f2da8a
ftp://updates.redhat.com/rhn/public/NULL/cups-libs/1.1.17-13.3.70/x86_64/cups-libs-1.1.17-13.3.70.x86_64.rpm
Missing file
    MD5: e4330a0505f064a1e9a709d45d8a6fdc
SHA-256: 286e646e2812e7ce803c852a78671448c20586ac7660b6f53f70bddc3c87c374
 

Bugs fixed (see bugzilla for more information)

595245 - CVE-2010-3702 xpdf: uninitialized Gfx::parser pointer dereference


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/