[Bluewhite64 Linux Security] cups [BW64SA:20090428-01]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


[Bluewhite64 Linux Security] cups [BW64SA:20090428-01]

New cups packages are available for Bluewhite64 Linux 12.0, 12.1, 12.2, and -current to
fix security issues.

More details about this issue may be found in the Common
Vulnerabilities and Exposures (CVE) database:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0163
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0164
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166


Here are the details from the Bluewhite64 12.2 ChangeLog:
- ----------------------------------------------------------
PATCHES/packages/cups-1.3.10-x86_64-1.tgz: Upgraded to cups-1.3.10.
This fixes several security issues, including an integer overflow in the TIFF
decoder, a failure to properly verify the Host HTTP header, and several
problems with PDF handling (the new CUPS uses a wrapper rather than embedded
code taken from xpdf). These issues could result in a denial of service or
the execution of arbitrary code.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0163
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0164
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166
[*** Security fix ***]




Download the new packages from:
- --------------------------------
For Bluewhite64 Linux 12.0:
http://data.bluewhite64.com/bluewhite64-12.0/patches/packages/cups-1.3.10-x86_64-1.tgz

For Bluewhite64 Linux 12.1:
http://data.bluewhite64.com/bluewhite64-12.1/patches/packages/cups-1.3.10-x86_64-1.tgz

For Bluewhite64 Linux 12.2:
http://data.bluewhite64.com/bluewhite64-12.2/patches/packages/cups-1.3.10-x86_64-1.tgz

For Bluewhite64 Linux -current:
http://data.bluewhite64.com/bluewhite64-current/bluewhite64/a/cups-1.3.10-x86_64-1.tgz

Also, please see the "Get Bluewhite64" section on http://www.bluewhite64.com for
additional mirror sites near you.


MD5 signatures:
- ----------------
Bluewhite64 12.0 package:
5f6ef882139bea9820b1cceb6437d026 cups-1.3.10-x86_64-1.tgz

Bluewhite64 12.1 package:
93dd2acec119057800b51c57a1bba32a cups-1.3.9-x86_64-1.tgz

Bluewhite64 12.2 package:
a75393dfb3aa651d7941e12b5bc7edb3 cups-1.3.10-x86_64-1.tgz

Bluewhite64 -current package:
02a0f5b0c2dd20cfbf7f4144c7735b70 cups-1.3.10-x86_64-1.tgz



Installation instructions:
- ----------------------------
Upgrade the package as root:
# upgradepkg cups-1.3.10-x86_64-1.tgz

If the server/Desktop is running the CUPS server, restart it:

# sh /etc/rc.d/rc.cups restart

- ---
Bluewhite64 Linux Security Team
http://bluewhite64.com/gpg-key

security©bluewhite64.com



- ------------------------------------------------------
To leave the bluewhite64-security mailing list:
Send a blank email to

bluewhite64-security-unsubscribe©bluewhite64.com

You will get a confirmation message back containing
instructions to complete the process.

Please do not reply to this email address.
- ------------------------------------------------------


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkn22h4ACgkQpTOsxuDdlY5gXACfb9FQi/lX9K0V8HDLvE0vbXx3
X6UAmwSUFnAAqBXN3vCHf8zPYOMk+OvB
=9cp5
-----END PGP SIGNATURE-----