Release Info

Advisory: CLSA-2022:1661441409

OS: Ubuntu 16.04 ELS

Public date: 2022-08-25 00:00:00

Project: cups

Version: 2.1.3-4ubuntu0.11+tuxcare.els1

Errata link: https://errata.cloudlinux.com/ubuntu16-els/CLSA-2022-1661441409.html

Changelog

* SECURITY UPDATE: Buffer overflow in ippReadIO - debian/patches/CVE-2019-8842.patch: fix check in cups/ipp.c - CVE-2019-8842 * SECURITY UPDATE: Buffer overflow in ippReadIO - debian/patches/CVE-2020-10001.patch: fix bounds checks in cups/ipp.c - CVE-2020-10001 * SECURITY UPDATE: Local authorization cert bypass - debian/patches/CVE-2022-26691.patch: fix string comparison in scheduler/cert.c - CVE-2022-26691

Update

Update command: apt-get update apt-get --only-upgrade install cups*

Packages list

cups_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb cups-bsd_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb cups-client_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb cups-common_2.1.3-4ubuntu0.11+tuxcare.els1_all.deb cups-core-drivers_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb cups-daemon_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb cups-ipp-utils_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb cups-ppdc_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb cups-server-common_2.1.3-4ubuntu0.11+tuxcare.els1_all.deb libcups2_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb libcups2-dev_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb libcupscgi1_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb libcupscgi1-dev_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb libcupsimage2_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb libcupsimage2-dev_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb libcupsmime1_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb libcupsmime1-dev_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb libcupsppdc1_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb libcupsppdc1-dev_2.1.3-4ubuntu0.11+tuxcare.els1_amd64.deb

CVEs

CVE-2020-10001
CVE-2019-8842
CVE-2022-26691