Bug 3979 - foomatic-filters missing security update for CVE-2011-2697 and CVE-2011-2964
Summary: foomatic-filters missing security update for CVE-2011-2697 and CVE-2011-2964
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 1
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL:
Whiteboard:
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2012-01-01 03:27 CET by David Walser
Modified: 2012-02-28 17:04 CET (History)
5 users (show)

See Also:
Source RPM: foomatic-filters-4.0.5-1.mga1.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2012-01-01 03:27:45 CET
Mandriva issued this advisory on August 14:
http://lists.mandriva.com/security-announce/2011-08/msg00007.php

This can be fixed by using the patches from MDV or by updating to 4.0.9.
Comment 1 Manuel Hiebel 2012-01-01 12:38:20 CET
Hi, thanks for reporting this bug.
Assigned to the package maintainer.

(Please set the status to 'assigned' if you are working on it)

Keywords: (none) => Triaged
Assignee: bugsquad => dmorganec

Comment 2 Manuel Hiebel 2012-01-16 17:03:40 CET
Ping ?
Comment 3 Manuel Hiebel 2012-02-01 11:05:56 CET
Ping ?

CC: (none) => thierry.vignaud

Comment 4 David Walser 2012-02-18 23:27:55 CET
Now the current version is 4.0.12, which contains another security fix:
"SECURITY FIX: Use the mktemp shell command and the mkstemp() C function to create debug files with unpredictable names (Thanks to Tim Waugh from Red Hat for the patch)."

The upstream website is now here:
http://www.linuxfoundation.org/collaborate/workgroups/openprinting

The Cauldron package needs to be updated as well.

On an unrelated note, the CUPS filters mentioned on their website should also be packaged for Cauldron.
Comment 5 David Walser 2012-02-26 18:37:40 CET
Patched package built.

Advisory:
========================

Updated foomatic-filters package fixes security vulnerabilities:

foomatic-rip in foomatic-filters before 4.0.8 allows remote attackers
to execute arbitrary code via a crafted *FoomaticRIPCommandLine field
in a .ppd file (CVE-2011-2697, CVE-2011-2964).

foomatic-rip in foomatic-filters before 4.0.12, writing debug file
output in debugging mode is performed insecurely (CVE-2011-2924).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2964
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2697
http://www.mandriva.com/en/support/security/advisories/?dis=2010.1&name=MDVSA-2011:125
https://bugs.linuxfoundation.org/show_bug.cgi?id=936
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2924
========================

Updated packages in core/updates_testing:
========================
foomatic-filters-4.0.5-1.1.mga1

from foomatic-filters-4.0.5-1.1.mga1.src.rpm

CC: (none) => dmorganec
Assignee: dmorganec => qa-bugs

Comment 6 Dave Hodgins 2012-02-27 06:48:32 CET
It's working fine on my i586 system.

Is this update complex enough that we should post a request
for more general testing before validating, or is the limited
qa hardware enough for testing this update?

CC: (none) => davidwhodgins

Comment 7 David Walser 2012-02-27 12:13:39 CET
(In reply to comment #6)
> It's working fine on my i586 system.
> 
> Is this update complex enough that we should post a request
> for more general testing before validating, or is the limited
> qa hardware enough for testing this update?

It's not a very complex update.  It just changes some tmp file handling and parsing of certain command line options that wouldn't be used in normal situations.  As long as foomatic-rip still works, there's no functional difference to before.
Comment 8 Dave Hodgins 2012-02-27 19:50:42 CET
Thanks for the answer.  Once this can be confirmed on x86-64
by for example, printing a page of a pdf document, the update
can be validated.
Comment 9 claire robinson 2012-02-28 10:33:57 CET
Tested x86_64 with:

foomatic-rip --ppd=/etc/cups/ppd/Cups-PDF.ppd -v <somefile>

Update validated

Could sysadmin please push from core/updates_testing to core/updates

Please see comment 5 for details

Thankyou!

Keywords: Triaged => validated_update
CC: (none) => sysadmin-bugs
Hardware: i586 => All

Comment 10 Thomas Backlund 2012-02-28 17:04:19 CET
update pushed

Status: NEW => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.