[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 314-1] cups security update

Package        : cups
Version        : 1.4.4-7+squeeze10
CVE ID         : CVE-2015-3258 CVE-2015-3279

Petr Sklenar of Red Hat discovered that the texttopdf tool, part of cups
filters, was susceptible to multiple heap-based buffer and integer overflows
due to improper handling of print jobs. This could allow remote attackers to
crash texttopdf or possibly execute arbitrary code.

For Debian 6 "Squeeze", this issue has been fixed in cups version
1.4.4-7+squeeze10. For Wheezy and Jessie, this has been fixed in the
cups-filter package. We recommend you to upgrade your cups packages.

Learn more about the Debian Long Term Support (LTS) Project and how to
apply these updates at: https://wiki.debian.org/LTS/

Attachment: signature.asc
Description: Digital signature

Reply to: