Your message dated Sun, 06 Oct 2024 16:32:38 +0000 with message-id <e1sxubs-00cpfi...@fasolo.debian.org> and subject line Bug#1082827: fixed in cups-filters 1.28.17-3+deb12u1 has caused the Debian Bug report #1082827, regarding cups-filters: CVE-2024-47076 to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact ow...@bugs.debian.org immediately.) -- 1082827: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1082827 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems
--- Begin Message ---Source: libcupsfilters Version: 2.0.0-2 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org> Hi, The following vulnerability was published for libcupsfilters. CVE-2024-47076[0]: | CUPS is a standards-based, open-source printing system, and | `libcupsfilters` contains the code of the filters of the former | `cups-filters` package as library functions to be used for the data | format conversion tasks needed in Printer Applications. The | `cfGetPrinterAttributes5` function in `libcupsfilters` does not | sanitize IPP attributes returned from an IPP server. When these IPP | attributes are used, for instance, to generate a PPD file, this can | lead to attacker controlled data to be provided to the rest of the | CUPS system. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2024-47076 https://www.cve.org/CVERecord?id=CVE-2024-47076 [1] https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-w63j-6g73-wmg5 [2] https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/ [3] https://github.com/OpenPrinting/libcupsfilters/commit/95576ec3d20c109332d14672a807353cdc551018 Regards, Salvatore
--- End Message ---
--- Begin Message ---Source: cups-filters Source-Version: 1.28.17-3+deb12u1 Done: Thorsten Alteholz <deb...@alteholz.de> We believe that the bug you reported is fixed in the latest version of cups-filters, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1082...@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Thorsten Alteholz <deb...@alteholz.de> (supplier of updated cups-filters package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmas...@ftp-master.debian.org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 26 Sep 2024 23:45:05 +0200 Source: cups-filters Architecture: source Version: 1.28.17-3+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: Debian Printing Team <debian-printing@lists.debian.org> Changed-By: Thorsten Alteholz <deb...@alteholz.de> Closes: 1082820 1082827 Changes: cups-filters (1.28.17-3+deb12u1) bookworm-security; urgency=high . * CVE-2024-47076 (Closes: #1082827) cfGetPrinterAttributes5(): Validate response attributes before return * CVE-2024-47176 (Closes: #1082820) Default BrowseRemoteProtocols should not include "cups" protocol Checksums-Sha1: 69e84346802d34af037726e757d75907cf65aeb8 3013 cups-filters_1.28.17-3+deb12u1.dsc 916cc1ebc2533a745b8a04233700d559ab91ed87 1511993 cups-filters_1.28.17.orig.tar.gz 3150250b38d18b60b19f3b285c93aeae9ffc0c78 86864 cups-filters_1.28.17-3+deb12u1.debian.tar.xz 0a3ae6f538460d5ba79614460790d76ed3cd61f5 9989 cups-filters_1.28.17-3+deb12u1_source.buildinfo Checksums-Sha256: b7f5b3e397a851ff64f002b8a3315907ad228c872832071f8e7368812fc40e50 3013 cups-filters_1.28.17-3+deb12u1.dsc ade6e4327e7eba1646881aaa4ca82a0df5d44e3b3b16326a5d3f04e975ab595c 1511993 cups-filters_1.28.17.orig.tar.gz bf368f1104cec4f0c50414d9e8b4bf9e267cc96eeee607423c28c946015febac 86864 cups-filters_1.28.17-3+deb12u1.debian.tar.xz 1ea2d4daf023d83fdc053d99ae3c9ef5faf67694e8c44a5c508d790a49345a4d 9989 cups-filters_1.28.17-3+deb12u1_source.buildinfo Files: 93eb72dd8018d31ea3b19db261fe3eff 3013 net optional cups-filters_1.28.17-3+deb12u1.dsc 389aa99780c9b5ac012fc4b2d29e5cba 1511993 net optional cups-filters_1.28.17.orig.tar.gz 1848fc6d71d97dc47119f63ad11e9183 86864 net optional cups-filters_1.28.17-3+deb12u1.debian.tar.xz f8922db6dffbb1739714237ac00beb21 9989 net optional cups-filters_1.28.17-3+deb12u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmb4GF5fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYRyDGD/9AN3Xh3QekmOzdLkMMHwyWf5mtoqhb uMHdy9NH3Q6M2h3ewS62IDQmTlq7viMbF1INSbvrPJcJo4A3EuBgvF90J9H04bDG 6A0/5FNdvG/obk/WtEaR+7C+ELApRIk7SnqNXNa8wF607/bJ9KckIpItTwAsxnNj S8QteFSJt3nZITrALlwcQRaYRo4mAgL6H73sPGi2GQto80xAek6KFvIQNsvSsKMQ 4G0L1vtEoTQ9ZZ44cgP3zgFmSPJc2BO4F86U3h3kjxTszzLs6txnB6ChbZCizHob aYVJXKAJpxD0joiIZvtB8sAfegIwhr6oVUh5lEkjtrad0qDqptmWr6UHYW6XDPlQ ejWqOD0keZm5Bjqk13sgfSFxnKwYkGiP8qCfGRZ5G9xDhnwFo+DwlOtS+YhhjFs/ Q+xO6T4i75ZXjbWrNh2IEOUyrcxJklaRfM4QshRlU2HCfR85/3GIWHuSboNRNCt5 PVgELgT38bY4FysqxvznHslAp3liZYQ7OV45I2/ROJsQ6Dx8mGkP4lx5ErTfwv1G 4yR93KM06PNwab+88rCHFLNXH1A7o+QRQ1ZOw5t87jrIwbToXiglxqVgTmQ2gHU5 EStYVpVOmngExN1R3pMTyXrulzLbXbGBzyEyVwccdAigafB07nEgGoRNccR9xTN3 GdFIoODujFEoZA== =mUxM -----END PGP SIGNATURE-----pgpvMFBuJYkNN.pgp
Description: PGP signature
--- End Message ---