Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 719052 - <net-print/cups-filters-1.27.4: Multiple vulnerabilities
Summary: <net-print/cups-filters-1.27.4: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa]
Keywords:
: 717236 (view as bug list)
Depends on:
Blocks:
 
Reported: 2020-04-23 13:51 UTC by Sam James
Modified: 2020-06-20 01:39 UTC (History)
2 users (show)

See Also:
Package list:
=net-print/cups-filters-1.27.4
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-04-23 13:51:13 UTC
After reviewing the changelog for cups-filters, I think there are a few dubious mentions of memory issues in there.

* Issue 1 

Description:
"cups-browsed: check_printer_with_option() function: Initialize the value, add further checks, freeing memory and stop allocating magic numbers (Pull request #204)."

Patch: https://github.com/OpenPrinting/cups-filters/pull/204/commits/dd376bc1a3e2f1cd85cc7b41b25df334362f0101

Fixed in: 1.27.2

* Issue 2

Description:
"cups-browsed: Additional checks against crashes in the is_local_hostname() function (Ubuntu bug 1863716)"

Patch: https://github.com/OpenPrinting/cups-filters/commit/4157690bf0a40be1030ed19da7f70d41b9f27f86

Fixed in: 1.27.2

* Issue 3

Description:
"Fix wrong pointer arithmetics - it lead to underflow when ghostscript returns error and crash."

Patch: https://github.com/OpenPrinting/cups-filters/commit/8a2ede9fcd7533053f67b394fcaaacc332c86b65

Fixed in: 1.27.2

* Issue 4

Description:
"libcupsfilters, cups-browsed: Fix memory issues in ppdgenerator and cups-browsed (Pull request 226)."

Patch: https://github.com/OpenPrinting/cups-filters/pull/226/commits/5d2f8d0ce8e4c3fe0bd6e22f4c367e731c06cb20

Fixed in: 1.27.4

---
There's a few other minor bits in 1.27.0, 1.27.1, but these look the most interesting.
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-04-23 13:51:47 UTC
@maintainer(s), please advise if ready for stabilisation, or call yourself
Comment 2 Andreas Sturmlechner gentoo-dev 2020-05-02 21:57:54 UTC
*** Bug 717236 has been marked as a duplicate of this bug. ***
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-04 09:42:39 UTC
@maintainer(s), I will stable this in a few days if no objections because astrum's bug had no complaints either.
Comment 4 Agostino Sarubbo gentoo-dev 2020-05-08 06:39:52 UTC
amd64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2020-05-08 17:12:16 UTC
ppc stable
Comment 6 Agostino Sarubbo gentoo-dev 2020-05-08 17:15:30 UTC
sparc stable
Comment 7 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-08 21:04:55 UTC
arm64 stable
Comment 8 Agostino Sarubbo gentoo-dev 2020-05-09 07:43:56 UTC
arm stable
Comment 9 Agostino Sarubbo gentoo-dev 2020-05-09 07:47:05 UTC
ppc64 stable
Comment 10 Rolf Eike Beer archtester 2020-05-09 19:53:22 UTC
hppa stable.
Comment 11 Agostino Sarubbo gentoo-dev 2020-05-11 11:39:20 UTC
x86 stable
Comment 12 Agostino Sarubbo gentoo-dev 2020-05-13 10:06:35 UTC
s390 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 13 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-18 02:34:11 UTC
@maintainer(s), ping, please cleanup
Comment 14 Larry the Git Cow gentoo-dev 2020-06-20 01:39:02 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7bbd043bee9acc55d36cb869cfc8d629de08c81e

commit 7bbd043bee9acc55d36cb869cfc8d629de08c81e
Author:     Aaron Bauman <bman@gentoo.org>
AuthorDate: 2020-06-20 01:38:04 +0000
Commit:     Aaron Bauman <bman@gentoo.org>
CommitDate: 2020-06-20 01:38:53 +0000

    net-print/cups-filters: drop vulnerable
    
    Bug: https://bugs.gentoo.org/719052
    Signed-off-by: Aaron Bauman <bman@gentoo.org>

 net-print/cups-filters/Manifest                    |   4 -
 net-print/cups-filters/cups-filters-1.25.11.ebuild | 139 ---------------------
 net-print/cups-filters/cups-filters-1.25.13.ebuild | 139 ---------------------
 net-print/cups-filters/cups-filters-1.26.2.ebuild  | 139 ---------------------
 net-print/cups-filters/cups-filters-1.27.2.ebuild  | 138 --------------------
 5 files changed, 559 deletions(-)