MGASA-2020-0248

Source
https://advisories.mageia.org/MGASA-2020-0248.html
Import Source
https://advisories.mageia.org/MGASA-2020-0248.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0248
Related
Published
2020-06-10T22:26:12Z
Modified
2020-06-10T21:55:12Z
Summary
Updated cups packages fix security vulnerability
Details

Updated cups packages fix security vulnerabilities:

It was discovered that CUPS incorrectly handled certain language values. A local attacker could possibly use this issue to cause CUPS to crash, leading to a denial of service, or possibly obtain sensitive information (CVE-2019-2228).

Stephan Zeisberg discovered that the CUPS SNMP backend incorrectly handled encoded ASN.1 inputs. A remote attacker could possibly use this issue to cause CUPS to crash by providing specially crafted network traffic (CVE-2019-8675, CVE-2019-8696).

The ippReadIO function may under-read an extension (CVE-2019-8842).

Stephan Zeisberg discovered that CUPS incorrectly handled certain malformed ppd files. A local attacker could possibly use this issue to execute arbitrary code (CVE-2020-3898).

The cups package has been updated to version 2.2.13 and patched to fix these issues and other bugs.

Also, this update will hopefully fix the cups service failing to start at boot on some systems.

References
Credits

Affected packages

Mageia:7 / cups

Package

Name
cups
Purl
pkg:rpm/mageia/cups?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.13-1.2.mga7

Ecosystem specific

{
    "section": "core"
}