oss-sec mailing list archives

Re: cups patches for CVE-2008-0597 and CVE-2008-0596


From: Tomas Hoger <thoger () redhat com>
Date: Mon, 28 Jul 2008 09:15:55 +0200

Hi Steffen!

On Sun, 27 Jul 2008 21:03:54 +0200 Robert Buchholz <rbu () gentoo org>
wrote:

I am working on a cups update at the moment and I am looking for two
missing patches. Could somebody please email me the patches for
CVE-2008-0596 and CVE-2008-0597 (both DoS due to crafted IPP packets
and a large number of requests for adding and removing printers).
I saw them marked as fixed in the opensuse announcement, but
couldn't find the patches for some reason and the novell bugzilla
does not grant access to the bugs to everyone :/
Thanks heaps in advance.

[ ... ]

the RedHat Bugzilla does not link the patches directly, but you can 
easily extract them from this SRPM:
ftp://updates.redhat.com/enterprise/3desktop/en/os/SRPMS/cups-1.1.17-13.3.51.src.rpm

I've attached the patches from Red Hat Enterprise Linux 4 packages to
our Bugzilla:

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-0596#c5
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-0597#c6

Both issues should only affect old cups versions (rough guess is
pre-1.2, but we haven't really investigated where exactly they got
fixed), so as the version in Etch is 1.2.7, you probably do not need to
care.  They were not needed for 1.2.4 in RHEL5 according to our
maintainer.

HTH

-- 
Tomas Hoger / Red Hat Security Response Team


Current thread: