USN-539-1: CUPS vulnerability
6 November 2007
CUPS vulnerability
Releases
Packages
- cupsys -
Details
Alin Rad Pop discovered that CUPS did not correctly validate buffer
lengths when processing IPP tags. Remote attackers successfully
exploiting this vulnerability would gain access to the non-root CUPS user
in Ubuntu 6.06 LTS, 6.10, and 7.04. In Ubuntu 7.10, attackers would be
isolated by the AppArmor CUPS profile.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 7.10
Ubuntu 7.04
Ubuntu 6.10
Ubuntu 6.06
In general, a standard system upgrade is sufficient to effect the
necessary changes.