Bug 25317 - cups new security issues CVE-2019-8675 and CVE-2019-8696
Summary: cups new security issues CVE-2019-8675 and CVE-2019-8696
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Thierry Vignaud
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on: 25874
Blocks: 23306
  Show dependency treegraph
 
Reported: 2019-08-16 14:55 CEST by David Walser
Modified: 2020-06-11 00:30 CEST (History)
0 users

See Also:
Source RPM: cups-2.2.11-2.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2019-08-16 14:55:00 CEST
CUPS 2.2.12 has been released on August 15, fixing two security issues:
https://github.com/apple/cups/releases/tag/v2.2.12

Mageia 6 and Mageia 7 are also affected.
David Walser 2019-08-16 14:55:20 CEST

Whiteboard: (none) => MGA7TOO, MGA6TOO
Blocks: (none) => 23306
Status comment: (none) => Fixed upstream in 2.2.12

Comment 1 Lewis Smith 2019-08-16 21:24:47 CEST
Assigning to the registered CUPS maintainer, tv.

Assignee: bugsquad => thierry.vignaud

Comment 2 David Walser 2019-08-28 22:26:26 CEST
Ubuntu has issued an advisory for this on August 20:
https://usn.ubuntu.com/4105-1/

Severity: normal => major

Comment 3 David Walser 2019-12-03 22:27:34 CET
openSUSE has issued an advisory for this on November 27:
https://lists.opensuse.org/opensuse-updates/2019-11/msg00154.html

Whiteboard: MGA7TOO, MGA6TOO => MGA7TOO

Comment 4 David Walser 2019-12-03 22:28:54 CET
tv updated Cauldron to 2.2.12 on August 30.

Whiteboard: MGA7TOO => (none)
Version: Cauldron => 7

David Walser 2020-01-14 17:32:56 CET

Depends on: (none) => 25874

Comment 6 David Walser 2020-04-29 02:39:37 CEST
RedHat has issued an advisory for this today (April 28):
https://access.redhat.com/errata/RHSA-2020:1765
David Walser 2020-05-22 19:51:00 CEST

Source RPM: cups-2.2.11-3.mga8.src.rpm => cups-2.2.11-2.mga7.src.rpm

Comment 7 David Walser 2020-05-22 23:46:19 CEST
Fix assigned to QA in Bug 26531.

Status comment: Fixed upstream in 2.2.12 => (none)

Comment 8 David Walser 2020-06-11 00:30:59 CEST
Fixed in:
https://advisories.mageia.org/MGASA-2020-0248.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.