Dit bericht is nog niet vertaald

[USN-539-1] CUPS vulnerability

Ubuntu Security Notice USN-539-1          November 06, 2007
cupsys vulnerability
CVE-2007-4351
Kwetsbare Ubuntu versies:

Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10

Kwetsbare pakketten:

Ubuntu 6.06 LTS
cupsys 1.2.2-0ubuntu0.6.06.4
Ubuntu 6.10
cupsys 1.2.4-2ubuntu3.1
Ubuntu 7.10
cupsys 1.3.2-1ubuntu7.1
Ubuntu 7.04
cupsys 1.2.8-0ubuntu8.1

In general, a standard system upgrade is sufficient to affect the necessary changes.

Alin Rad Pop discovered that CUPS did not correctly validate buffer lengths when processing IPP tags. Remote attackers successfully exploiting this vulnerability would gain access to the non-root CUPS user in Ubuntu 6.06 LTS, 6.10, and 7.04. In Ubuntu 7.10, attackers would be isolated by the AppArmor CUPS profile.