Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in Foomatic
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in Foomatic
ID: FEDORA-2011-9554
Distribution: Fedora
Plattformen: Fedora 15
Datum: Mi, 17. August 2011, 08:55
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2697
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2964
Applikationen: Foomatic

Originalnachricht

-------------------------------------------------------------------------------
-
Fedora Update Notification
FEDORA-2011-9554
2011-07-22 19:06:19
-------------------------------------------------------------------------------
-

Name : foomatic
Product : Fedora 15
Version : 4.0.7
Release : 3.fc15
URL : http://www.linuxprinting.org
Summary : Tools for using the foomatic database of printers and printer
drivers
Description :
Foomatic is a comprehensive, spooler-independent database of printers,
printer drivers, and driver descriptions. This package contains
utilities to generate driver description files and printer queues for
CUPS, LPD, LPRng, and PDQ using the database (packaged separately).
There is also the possibility to read the PJL options out of PJL-capable
laser printers and take them into account at the driver description
file generation.

There are spooler-independent command line interfaces to manipulate
queues (foomatic-configure) and to print files/manipulate jobs
(foomatic printjob).

The site http://www.linuxprinting.org/ is based on this database.

-------------------------------------------------------------------------------
-
Update Information:

This update fixes improper sanitization of command line options.
(CVE-2011-2964)
-------------------------------------------------------------------------------
-
ChangeLog:

* Wed Jul 20 2011 Tim Waugh <twaugh@redhat.com> - 4.0.7-3
- Fix improper sanitization of command line options (bug #721001,
CVE-2011-2697).
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #727016 - CVE-2011-2964 foomatic: Improper sanitization of command
line option in foomatic-rip (foomatic.c)
https://bugzilla.redhat.com/show_bug.cgi?id=727016
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update foomatic' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung