This bug was fixed in the package libppd - 2:2.1~b1-0ubuntu2 --------------- libppd (2:2.1~b1-0ubuntu2) oracular; urgency=medium
* SECURITY UPDATE: PPD injection issues (LP: #2082335) - debian/patches/sec-202409-1.patch: sanitize and validate IPP values in generated PPD file in ppd/ppd-cache.c, ppd/ppd-generator.c. - debian/patches/sec-202409-2.patch: escape localized strings in ppd/ppd-generator.c. - debian/patches/sec-202409-3.patch: fix FTBFS and default InputSlot value in ppd/ppd-cache.c, ppd/ppd-generator.c. - CVE-2024-47175 -- Marc Deslauriers <marc.deslauri...@ubuntu.com> Thu, 26 Sep 2024 09:27:49 -0400 ** Changed in: libppd (Ubuntu Oracular) Status: Fix Committed => Fix Released ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-47175 ** Changed in: libcupsfilters (Ubuntu Oracular) Status: Fix Committed => Fix Released ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-47076 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/2082335 Title: Sept 2024 security issue tracking bug Status in cups package in Ubuntu: Fix Committed Status in cups-browsed package in Ubuntu: Fix Committed Status in cups-filters package in Ubuntu: Invalid Status in libcupsfilters package in Ubuntu: Fix Released Status in libppd package in Ubuntu: Fix Released Status in cups source package in Focal: Fix Released Status in cups-browsed source package in Focal: Invalid Status in cups-filters source package in Focal: Fix Released Status in libcupsfilters source package in Focal: Invalid Status in libppd source package in Focal: Invalid Status in cups source package in Jammy: Fix Released Status in cups-browsed source package in Jammy: Invalid Status in cups-filters source package in Jammy: Fix Released Status in libcupsfilters source package in Jammy: Invalid Status in libppd source package in Jammy: Invalid Status in cups source package in Noble: Fix Released Status in cups-browsed source package in Noble: Fix Released Status in cups-filters source package in Noble: Invalid Status in libcupsfilters source package in Noble: Fix Released Status in libppd source package in Noble: Fix Released Status in cups source package in Oracular: Fix Committed Status in cups-browsed source package in Oracular: Fix Committed Status in cups-filters source package in Oracular: Invalid Status in libcupsfilters source package in Oracular: Fix Released Status in libppd source package in Oracular: Fix Released Bug description: This bug is to track the vulnerabilities in the cups and associated packages. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/cups/+bug/2082335/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp