Markus, Although I accepted this, soon after I am seeing this failure
https://autobuilder.yoctoproject.org/typhoon/#/builders/88/builds/3341/steps/14/logs/stdio I wonder if its some sort of race condition ? On Mon, Nov 13, 2023 at 10:33 AM Khem Raj <[email protected]> wrote: > > > On Sun, 12 Nov 2023 01:59:41 +0100, Markus Volk wrote: > > - `universal`: Enable `application/vnd.cups-postscript` as input > > There are filters which produce this MIME type (such as `hpps` of > > HPLIP), and if someone uses such driver on a client and the server > > has an IPP Everywhere/driverless printer, the job fails (Pull > > request #534). > > > > - beh backend: Use `execv()` instead of `system()` - CVE-2023-24805 > > With `execv()` command line arguments are passed as separate strings > > and not the full command line in a single string. This prevents > > arbitrary command execution by escaping the quoting of the arguments > > in a job with forged job title. > > > > [...] > > Applied, thanks! > > [1/1] cups-filters: Upgrade 1.28.17 -> 2.0.0 > commit: 71e6fa9b086cdd8c0c30afbda48c2f40add8cded > > Best regards, > -- > Khem Raj <[email protected]> >
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#106724): https://lists.openembedded.org/g/openembedded-devel/message/106724 Mute This Topic: https://lists.openembedded.org/mt/102536178/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-devel/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
