On Sun, 12 Nov 2023 01:59:41 +0100, Markus Volk wrote:
> - `universal`: Enable `application/vnd.cups-postscript` as input
> There are filters which produce this MIME type (such as `hpps` of
> HPLIP), and if someone uses such driver on a client and the server
> has an IPP Everywhere/driverless printer, the job fails (Pull
> request #534).
>
> - beh backend: Use `execv()` instead of `system()` - CVE-2023-24805
> With `execv()` command line arguments are passed as separate strings
> and not the full command line in a single string. This prevents
> arbitrary command execution by escaping the quoting of the arguments
> in a job with forged job title.
>
> [...]
Applied, thanks!
[1/1] cups-filters: Upgrade 1.28.17 -> 2.0.0
commit: 71e6fa9b086cdd8c0c30afbda48c2f40add8cded
Best regards,
--
Khem Raj <[email protected]>
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#106651):
https://lists.openembedded.org/g/openembedded-devel/message/106651
Mute This Topic: https://lists.openembedded.org/mt/102536178/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-devel/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-