Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Mon, 28 Jul 2008 09:15:55 +0200
From: Tomas Hoger <thoger@...hat.com>
To: oss-security@...ts.openwall.com
Cc: rbu@...too.org, Steffen Joeris <steffen.joeris@...lelinux.de>
Subject: Re: cups patches for CVE-2008-0597 and CVE-2008-0596

Hi Steffen!

On Sun, 27 Jul 2008 21:03:54 +0200 Robert Buchholz <rbu@...too.org>
wrote:

> > I am working on a cups update at the moment and I am looking for two
> > missing patches. Could somebody please email me the patches for
> > CVE-2008-0596 and CVE-2008-0597 (both DoS due to crafted IPP packets
> > and a large number of requests for adding and removing printers).
> > I saw them marked as fixed in the opensuse announcement, but
> > couldn't find the patches for some reason and the novell bugzilla
> > does not grant access to the bugs to everyone :/
> > Thanks heaps in advance.

[ ... ]

> the RedHat Bugzilla does not link the patches directly, but you can 
> easily extract them from this SRPM:
> ftp://updates.redhat.com/enterprise/3desktop/en/os/SRPMS/cups-1.1.17-13.3.51.src.rpm

I've attached the patches from Red Hat Enterprise Linux 4 packages to
our Bugzilla:

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-0596#c5
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-0597#c6

Both issues should only affect old cups versions (rough guess is
pre-1.2, but we haven't really investigated where exactly they got
fixed), so as the version in Etch is 1.2.7, you probably do not need to
care.  They were not needed for 1.2.4 in RHEL5 according to our
maintainer.

HTH

-- 
Tomas Hoger / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.