Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 115286 - net-print/cups xpdf holes (CAN-2005-319{1|2|3})
Summary: net-print/cups xpdf holes (CAN-2005-319{1|2|3})
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A2? [glsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2005-12-12 03:19 UTC by Thierry Carrez (RETIRED)
Modified: 2019-12-09 20:37 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thierry Carrez (RETIRED) gentoo-dev 2005-12-12 03:19:53 UTC
See bug 144428 for details. CUPS is traditionally affected by the same flaws so
this bug will track it.
Comment 1 Daniel Gryniewicz (RETIRED) gentoo-dev 2005-12-12 13:21:05 UTC
cups < cups-1.1.23-r3 is vulnerable.  Starting with -r3, we disable the internal
xpdf and use the xpdf package, so the fix for xpdf will make be sufficient for
cups.  Therefore, at least -r3 needs to go stable (preferably -r4, since that
has other fixes).

Target keywords: alpha amd64 arm hppa ia64 mips ppc ppc64 s390 sh sparc x86
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-12-12 13:26:30 UTC
Daniel good move, wish all other packages bundling xpdf could do the same:-) 
 
Arches please test and mark stable.  
  
Note: It's bug #114428 and not the one reported above.  
Comment 3 Daniel Gryniewicz (RETIRED) gentoo-dev 2005-12-12 20:40:30 UTC
amd64 done.
Comment 4 Gustavo Zacarias (RETIRED) gentoo-dev 2005-12-13 05:55:57 UTC
1.1.23-r4 sparc stable.
Comment 5 Markus Rothe (RETIRED) gentoo-dev 2005-12-13 08:45:56 UTC
1.1.23-r4 stable on ppc64. 
Comment 6 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-12-13 11:11:27 UTC
hppa, ppc done
Comment 7 Fernando J. Pereda (RETIRED) gentoo-dev 2005-12-14 03:58:52 UTC
Alpha done
Comment 8 Mark Loeser (RETIRED) gentoo-dev 2005-12-14 20:36:51 UTC
x86 done
Comment 9 Niels Werensteijn 2005-12-15 09:12:18 UTC
While I am all for security, this action makes cups dependend on x11-libs/libXt
(via xpdf). I enjoy running my server with cups and without X11 related
packages. Is there any way we can solve this?
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-12-15 23:57:20 UTC
GLSA 200512-08 
 
First round done. 
 
ia64, mips, s390, sh don't forget to mark stable to benifit from the GLSA. 
Comment 11 Thierry Carrez (RETIRED) gentoo-dev 2005-12-16 04:46:39 UTC
About comment #9, adding -motif to xpdf in package.use might prevent bringing X
deps in. In the event it doesn't solve it, please open a separate (non-security)
bug so that xpdf/CUPS maintainers can solve the problem.
Comment 12 Niels Werensteijn 2005-12-16 06:06:06 UTC
-motif worked. Sorry for posting in the wrong section.
Comment 13 Joshua 2006-01-03 10:55:27 UTC
There is a bit of a conflict for me. emerge kpdf and cups. Kpdf wants poppler and cups wants xpdf but I cannot install poppler and xpdf at same time
Comment 14 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-01-03 13:37:27 UTC
Joshua, currently non X applications are moving towards depending on poppler instead of xpdf. At the moment stable is broken, but the printing herd is working to get this fixed.
Comment 15 Daniel Gryniewicz (RETIRED) gentoo-dev 2006-01-08 16:40:21 UTC
You *can* install poppler and xpdf at the same time.  New poppler block old xpdf.  Unmerge xpdf, and let it's deps pull it back in, and all should be fine.