Bug 28277 - cups new security issue CVE-2020-10001
Summary: cups new security issue CVE-2020-10001
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-02-02 18:39 CET by David Walser
Modified: 2021-03-07 22:37 CET (History)
6 users (show)

See Also:
Source RPM: cups-2.3.3op1-1.mga8.src.rpm
CVE: CVE-2020-10001
Status comment:


Attachments

Description David Walser 2021-02-02 18:39:21 CET
SUSE has issued an advisory today (February 2):
https://lists.suse.com/pipermail/sle-security-updates/2021-February/008267.html

The issue is fixed upstream in 2.3.3op2.

Mageia 7 is also affected.
David Walser 2021-02-02 18:39:34 CET

Status comment: (none) => Fixed upstream in 2.3.3op2
Whiteboard: (none) => MGA7TOO

Comment 1 David Walser 2021-02-02 21:02:44 CET
cups-2.3.3op2-1.mga8 uploaded for Cauldron by Thierry.

Assignee: bugsquad => thierry.vignaud
Version: Cauldron => 7
Whiteboard: MGA7TOO => (none)

Comment 2 David Walser 2021-02-05 23:58:32 CET
openSUSE has issued an advisory for this today (February 5):
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EYJFJX2GGKH4VAMYMTSR5TZZO2F2HPHC/
Comment 3 David Walser 2021-02-08 16:29:32 CET
Fedora has issued an advisory for this on February 7:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/5UJW2PDBQXOWGEVBB2UJEFJCOTDQXG7H/
Comment 4 Nicolas Lécureuil 2021-03-04 18:55:22 CET
patch added in mga7:

src:
    - cups-2.2.13-1.5.mga7

Status comment: Fixed upstream in 2.3.3op2 => (none)
Assignee: thierry.vignaud => qa-bugs
CC: (none) => mageia

Comment 5 David Walser 2021-03-04 22:50:12 CET
RPMs:
cups-2.2.13-1.5.mga7
cups-common-2.2.13-1.5.mga7
libcups2-devel-2.2.13-1.5.mga7
libcups2-2.2.13-1.5.mga7
cups-filesystem-2.2.13-1.5.mga7
Comment 6 David Walser 2021-03-05 00:54:29 CET
Advisory:
========================

Updated cups packages fix security vulnerability:

Out-of-bounds read in the ippReadIO function (CVE-2020-10001).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10001
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EYJFJX2GGKH4VAMYMTSR5TZZO2F2HPHC/
Comment 7 PC LX 2021-03-05 10:53:26 CET
Installed and tested without issue.

Printer: HP Officejet 4658 (USB connection)
System: Mageia 7, x86_64, Plasma DE, LXQt DE, Intel CPU, nVidia GPU using nvidia-current proprietary driver.

Tested printing (color, gray) and scanning. HP Device Manager works without issues.


$ uname -a
Linux marte 5.10.19-desktop-1.mga7 #1 SMP Fri Feb 26 23:48:09 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux
$ rpm -qa | grep cups | sort
cups-2.2.13-1.5.mga7
cups-common-2.2.13-1.5.mga7
cups-drivers-foo2zjs-0.0-1.20121012.11.mga7
cups-filesystem-2.2.13-1.5.mga7
cups-filters-1.22.5-1.mga7
cups-pk-helper-0.2.6-3.mga7
gutenprint-cups-5.2.14-2.mga7
lib64cups2-2.2.13-1.5.mga7
lib64cups-filters1-1.22.5-1.mga7
libcups2-2.2.13-1.5.mga7
python3-cups-1.9.74-2.mga7
$ dmesg | tail -n 20 | grep usb
[ 3182.141668] usb 1-1: new high-speed USB device number 9 using ehci-pci
[ 3182.270520] usb 1-1: New USB device found, idVendor=03f0, idProduct=d911, bcdDevice= 1.00
[ 3182.270528] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3
[ 3182.270531] usb 1-1: Product: OfficeJet 4650 series
[ 3182.270534] usb 1-1: Manufacturer: HP
[ 3182.270536] usb 1-1: SerialNumber: <SNIP>
[ 3182.335359] usblp 1-1:1.1: usblp1: USB Bidirectional printer dev 9 if 1 alt 0 proto 2 vid 0x03F0 pid 0xD911
[ 3182.335403] usbcore: registered new interface driver usblp

CC: (none) => mageia

Comment 8 Thomas Andrews 2021-03-05 21:35:23 CET
Also installed  and tested without issues.

Printers: HP Deskjet 5650, Color Laserjet CP1215. Both connected via usb.
System: Mageia 7 x86_64, Plasma i5 2500, Intel i915 graphics.

Removed an old, now inoperable Officejet 6110, obtained updates, installed the Laserjet, printed test pages in color and monochrome. Left system-config-printer and opened the HP Device Manager. Printed another test page from the Laserjet and one from the Deskjet. Examined cups information for both.

Giving this an OK, and validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Whiteboard: (none) => MGA7-64-OK
Keywords: (none) => validated_update

Comment 9 Aurelien Oudelet 2021-03-06 14:27:21 CET
Agree, no regression on this M7 64 Plasma system.
Able to print and to change settings.

Advisory committed to SVN.

CVE: (none) => CVE-2020-10001
Keywords: (none) => advisory
CC: (none) => ouaurelien

Comment 10 Morgan Leijström 2021-03-06 20:58:05 CET
OK also here M7 64 Plasma, Canon on ethernet, and Boomaga

CC: (none) => fri

Comment 11 Mageia Robot 2021-03-07 22:37:24 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0116.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.