First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 201570
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
cups-SNMP-CVE-2007-5849.patch cups-SNMP-CVE-2007-5849.patch patch Robert Buchholz 2007-12-07 09:32 0000 935 bytes Details | Diff
cups-1.2.12-r4.ebuild cups-1.2.12-r4.ebuild text/plain Timo Gurr 2007-12-11 21:25 0000 6.89 KB Details
cups-1.3.4-r4.ebuild cups-1.3.4-r4.ebuild text/plain Timo Gurr 2007-12-11 21:25 0000 7.95 KB Details
cups-CVE-2007-5849.patch cups-CVE-2007-5849.patch text/plain Timo Gurr 2007-12-11 21:26 0000 1017 bytes Details
pdftops-1.20.gentoo pdftops-1.20.gentoo, fixing bug #201042 text/plain Timo Gurr 2007-12-11 21:27 0000 10.17 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 201570 depends on: Show dependency tree
Bug 201570 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-12-07 09:31 0000
Aaron Sigel reported to us a stack-based buffer overflow in the SNMP backend of
CUPS when parsing the reply to an SNMP print lookup request. Exploitation may
allow the remote execution of arbitrary code on the cups server.

I'll attach a patch. Stefan and Timo, do not commit anything to CVS yet, as
this issue is under embargo until Dec. 13. Please attach an updated ebuild to
this bug (possibly also addressing bug 201042 ?) and we will do prestable
testing here.

------- Comment #1 From Robert Buchholz 2007-12-07 09:32:59 0000 -------
Created an attachment (id=137954) [edit]
cups-SNMP-CVE-2007-5849.patch

------- Comment #2 From Robert Buchholz 2007-12-11 19:45:13 0000 -------
ping

------- Comment #3 From Timo Gurr 2007-12-11 21:25:31 0000 -------
Created an attachment (id=138275) [edit]
cups-1.2.12-r4.ebuild

------- Comment #4 From Timo Gurr 2007-12-11 21:25:48 0000 -------
Created an attachment (id=138277) [edit]
cups-1.3.4-r4.ebuild

------- Comment #5 From Timo Gurr 2007-12-11 21:26:22 0000 -------
Created an attachment (id=138279) [edit]
cups-CVE-2007-5849.patch

------- Comment #6 From Timo Gurr 2007-12-11 21:27:12 0000 -------
Created an attachment (id=138281) [edit]
pdftops-1.20.gentoo, fixing bug #201042

------- Comment #7 From Robert Buchholz 2007-12-11 21:34:53 0000 -------
Thanks.

Arch Security Liaisons, please test the attached ebuild (cups-1.2.12-r4) and
report it stable on this bug.
Target keywords : "alpha amd64 arm hppa ia64 m68k mips ppc ppc64 s390 sh sparc
x86"

CC'ing current Liaisons:
  alpha : ferdy
  amd64 : welp
   hppa : jer
    ppc : dertobi123
  ppc64 : corsair
  sparc : ferdy
    x86 : tsunam

For the change in the pdftops script, you should probably try printing a pdf
file with lp(r) on a ps printer.

------- Comment #8 From Robert Buchholz 2007-12-11 22:17:57 0000 -------
prints fine (well, at least not worse than before) on amd64.

------- Comment #9 From Christian Faulhammer 2007-12-12 08:34:30 0000 -------
(In reply to comment #7)
> For the change in the pdftops script, you should probably try printing a pdf
> file with lp(r) on a ps printer.

 PDF file to local PS printer ... ok
 PDF file to remote PS printer ... ok
 Test page from Windows to remote PCL printer ... ok

x86 is fine.

------- Comment #10 From Raúl Porcel 2007-12-12 14:30:03 0000 -------
Adding Ferris for sparc since i can't test this on sparc.

------- Comment #11 From Ferris McCormick 2007-12-12 15:21:29 0000 -------
Tested on sparc only with a remote printer, because that is all I have.  That
said, sparc is fine, both with .ps files and with .pdf files (using the
attached pdftops-1.20.gentoo filter).

That said, why is ferdy the sparc liaison for security bugs?  As far as I know,
he is not a sparc user, and he is not a sparc developer, last I knew.  Unless
you have a good reason not to, please use either me or armin76 as the sparc
arch contact.

------- Comment #12 From Raúl Porcel 2007-12-12 16:24:12 0000 -------
Adding Blackb|rd to alpha since nobody in the alpha team can test this, he's in
process of becoming a dev, so there's no problem.

------- Comment #13 From Robert Buchholz 2007-12-12 17:19:36 0000 -------
sorry, a typo above lists ferdy for sparc, while it should be fmccor. Ferris,
please excuse me and please test.

------- Comment #14 From Robert Buchholz 2007-12-12 17:22:44 0000 -------
(In reply to comment #11)
> That said, why is ferdy the sparc liaison for security bugs?  As far as I know,
> he is not a sparc user, and he is not a sparc developer, last I knew.  Unless
> you have a good reason not to, please use either me or armin76 as the sparc
> arch contact.

Blame me. Of course, you and Raul are our primary sparc contacts.

------- Comment #15 From Raúl Porcel 2007-12-12 17:23:52 0000 -------
Tobias (Blackb|rd) just tested it and says:
<Blackb|rd> Emerges fine on alpha.
<Blackb|rd> Printing of PDF, PS, TXT works, as does remote printing and printer
browsing.

He couldn't post in this bug, dunno why.

So alpha is okay, and ia64 as well.

Thanks Tobias

------- Comment #16 From Jeroen Roovers 2007-12-12 17:44:20 0000 -------
Works for HPPA.

------- Comment #17 From Markus Rothe 2007-12-12 18:46:19 0000 -------
looks good on ppc64, too.

------- Comment #18 From Tobias Scherbaum 2007-12-12 20:02:26 0000 -------
ppc looks good as well

------- Comment #19 From Robert Buchholz 2007-12-13 01:18:39 0000 -------
Disclosure of this vulnerability has been pushed to Monday, 17.12.

------- Comment #20 From Robert Buchholz 2007-12-17 23:42:05 0000 -------
This is public via http://www.cups.org/str.php?L2589

Printing, please commit this ebuild to the tree with stable keywords for the
arches that responded.

------- Comment #21 From Ferris McCormick 2007-12-17 23:51:18 0000 -------
(In reply to comment #13)
> sorry, a typo above lists ferdy for sparc, while it should be fmccor. Ferris,
> please excuse me and please test.
> 

As mentioned in Comment 11, sparc is fine.

------- Comment #22 From Robert Buchholz 2007-12-18 21:36:18 0000 -------
Arches, please test and mark stable net-print/cups-1.2.12-r4.
Target keywords : "alpha amd64 arm hppa ia64 m68k mips ppc ppc64 s390 sh sparc
x86"
Already stabled : "alpha amd64 hppa ia64 ppc ppc64 sparc x86"
Missing keywords: "arm m68k mips s390 sh"

------- Comment #23 From Robert Buchholz 2007-12-18 22:29:51 0000 -------
GLSA 200712-14, thanks everyone.

First Last Prev Next    No search results available      Search page      Enter new bug