From 2.4.3 release notes: """ Fixed possible heap buffer overflow in _cups_strlcpy() (fixes CVE-2023-32324) """
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=944d80c615574d3b1e7a9e2e060640b1b3cc5ff4 commit 944d80c615574d3b1e7a9e2e060640b1b3cc5ff4 Author: Sam James <sam@gentoo.org> AuthorDate: 2023-06-02 05:16:24 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2023-06-02 05:16:42 +0000 net-print/cups: add 2.4.3 Bug: https://bugs.gentoo.org/907675 Signed-off-by: Sam James <sam@gentoo.org> net-print/cups/Manifest | 1 + net-print/cups/cups-2.4.3.ebuild | 315 +++++++++++++++++++++++++++++++++++++++ net-print/cups/cups-9999.ebuild | 12 +- 3 files changed, 322 insertions(+), 6 deletions(-)
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=eabfd29399b97d885388cea671349c85f19e5b35 commit eabfd29399b97d885388cea671349c85f19e5b35 Author: Sam James <sam@gentoo.org> AuthorDate: 2023-09-27 04:19:23 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2023-09-27 04:19:23 +0000 net-print/cups: drop 2.4.2-r7, 2.4.4, 2.4.5 Bug: https://bugs.gentoo.org/907675 Bug: https://bugs.gentoo.org/909018 Signed-off-by: Sam James <sam@gentoo.org> net-print/cups/Manifest | 3 - net-print/cups/cups-2.4.2-r7.ebuild | 325 --------------------- net-print/cups/cups-2.4.4.ebuild | 315 -------------------- net-print/cups/cups-2.4.5.ebuild | 315 -------------------- .../files/cups-2.4.2-no-fortify-override.patch | 18 -- .../cups-2.4.2-openssl-intermediate-certs.patch | 20 -- .../cups/files/cups-2.4.2-scheduler-ipp.patch | 36 --- net-print/cups/files/cups-resolve-local.patch | 97 ------ 8 files changed, 1129 deletions(-)
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=e7fda950590c5976421bfc5b5694dcadd1281e90 commit e7fda950590c5976421bfc5b5694dcadd1281e90 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2024-02-18 08:55:48 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2024-02-18 08:56:12 +0000 [ GLSA 202402-17 ] CUPS: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/847625 Bug: https://bugs.gentoo.org/907675 Bug: https://bugs.gentoo.org/909018 Bug: https://bugs.gentoo.org/914781 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202402-17.xml | 48 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+)