| Summary: | cups new security issue CVE-2023-32360 and CVE-2023-4504 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Nicolas Salguero <nicolas.salguero> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, fri, herman.viaene, marja11, nicolas.salguero, sysadmin-bugs, thierry.vignaud |
| Version: | 9 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8TOO MGA8-64-OK MGA9-64-OK | ||
| Source RPM: | cups-2.4.6-1.mga9.src.rpm | CVE: | |
| Status comment: | |||
|
Description
Nicolas Salguero
2023-09-13 14:05:25 CEST
Nicolas Salguero
2023-09-13 14:05:49 CEST
CC:
(none) =>
nicolas.salguero Normally done by tv, other packagers are now committing it; so assigning globally, CC'ing Thierry. Note the M8; M9 is at v2.4.6. Assignee:
bugsquad =>
pkg-bugs Suggested advisory: ======================== The updated packages fix a security vulnerability: It was discovered that CUPS incorrectly authenticated certain remote requests. A remote attacker could possibly use this issue to obtain recently printed documents. (CVE-2023-32360) References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32360 https://ubuntu.com/security/notices/USN-6361-1 ======================== Updated packages in core/updates_testing: ======================== cups-2.3.3op2-1.4.mga8 cups-common-2.3.3op2-1.4.mga8 cups-filesystem-2.3.3op2-1.4.mga8 cups-printerapp-2.3.3op2-1.4.mga8 lib(64)cups2-2.3.3op2-1.4.mga8 lib(64)cups2-devel-2.3.3op2-1.4.mga8 from SRPM: cups-2.3.3op2-1.4.mga8.src.rpm Assignee:
pkg-bugs =>
nicolas.salguero
Nicolas Salguero
2023-09-18 09:23:14 CEST
Assignee:
nicolas.salguero =>
qa-bugs MGA8-64 Xfce on Acer Aspire No installation issues Reomved wifi HP Envy 6022 printer in MCC and added it again, and printed test page, all OK. CC:
(none) =>
herman.viaene Ubuntu has issued an advisory for CVE-2023-4504 on September 20: https://ubuntu.com/security/notices/USN-6391-1 The issue is fixed by: https://github.com/OpenPrinting/cups/commit/2431caddb7e6a87f04ac90b5c6366ad268b6ff31 Mageia 8 and 9 are also affected. Whiteboard:
(none) =>
MGA9TOO, MGA8TOO
Nicolas Salguero
2023-09-25 10:51:49 CEST
Status comment:
Fi =>
Fixed upstream in 2.4.7 Suggested advisory: ======================== The updated packages fix security vulnerabilities: It was discovered that CUPS incorrectly authenticated certain remote requests. A remote attacker could possibly use this issue to obtain recently printed documents. (CVE-2023-32360) Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. (CVE-2023-4504) References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32360 https://ubuntu.com/security/notices/USN-6361-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4504 https://ubuntu.com/security/notices/USN-6391-1 ======================== Updated packages in 9/core/updates_testing: ======================== cups-2.4.6-1.1.mga9 cups-common-2.4.6-1.1.mga9 cups-filesystem-2.4.6-1.1.mga9 cups-printerapp-2.4.6-1.1.mga9 lib(64)cups2-2.4.6-1.1.mga9 lib(64)cups2-devel-2.4.6-1.1.mga9 from SRPM: cups-2.4.6-1.1.mga9.src.rpm Updated packages in 8/core/updates_testing: ======================== cups-2.3.3op2-1.5.mga8 cups-common-2.3.3op2-1.5.mga8 cups-filesystem-2.3.3op2-1.5.mga8 cups-printerapp-2.3.3op2-1.5.mga8 lib(64)cups2-2.3.3op2-1.5.mga8 lib(64)cups2-devel-2.3.3op2-1.5.mga8 from SRPM: cups-2.3.3op2-1.5.mga8.src.rpm Source RPM:
cups-2.3.3op2-1.3.mga8.src.rpm =>
cups-2.4.6-1.mga9.src.rpm mga9-64 OK here, printing to an Ethernet printer, and to Boomaga. CC:
(none) =>
fri MGA8-64 Xfce on Acer Aspire No installation issues Removed wifi HP Envy 6022 printer in MCC and added it again, all OK. MGA9-64 Plasma, no installation issues. Printed a photo to a usb Color Laserjet CP1215 in monochrome. This printer uses the FOO2HP driver, rather than hplip. Worked OK, giving it a MGA9 OK, based on this test and comment 6. Whiteboard:
MGA8TOO =>
MGA8TOO MGA9-64-OK MGA8-Plasma, AMD Phenom II X4, Radeon HD 8490 graphics. Used qarepo to get the package candidates, then went to MCC and installed system-config-printer and dependencies, including cups. Added the Color Laserjet CP1215, and printed a test page. No issues to report. Giving this a MGA8 OK based on this test and comment 7. Validating. Advisory in comment 5. CC:
(none) =>
sysadmin-bugs An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2023-0284.html Status:
ASSIGNED =>
RESOLVED |