Description: | Description:
The remote host is missing an update to cups announced via advisory FEDORA-2008-8844.
Update Information:
Security release. This updates to 1.3.9 and fixes three integer overflows in the CUPS text and image filters.
ChangeLog:
* Fri Oct 10 2008 Tim Waugh 1:1.3.9-1 - 1.3.9, including fixes for CVE-2008-3639 / STR #2918, CVE-2008-3640 / STR #2919 and CVE-2008-3641 / STR #2911 (bug #466419). - No longer need str2892 or res_init patches. * Wed Sep 10 2008 Tim Waugh - Backported patch for FatalErrors configuration directive (bug #314941, STR #2536). * Wed Sep 3 2008 Tim Waugh - The dnssd backend uses avahi-browse so require it (bug #458565). - cups-polld: reinit the resolver if we haven't yet resolved the hostname (bug #354071).
References:
[ 1 ] Bug #464710 - CVE-2008-3639 CUPS: SGI image parser heap-based buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=464710 [ 2 ] Bug #464713 - CVE-2008-3640 CUPS: texttops integer overflow https://bugzilla.redhat.com/show_bug.cgi?id=464713 [ 3 ] Bug #464716 - CVE-2008-3641 CUPS: HP/GL reader insufficient bounds checking https://bugzilla.redhat.com/show_bug.cgi?id=464716
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update cups' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-8844
Risk factor : Critical
CVSS Score: 10.0
|