Re: cups-filters 1.2.0 released!
B0;115;0cOn Mon, Nov 30, 2015 at 10:21:58PM +0100, Didier 'OdyX' Raboud wrote:
> Hi Till,
>
> Le jeudi, 26 novembre 2015, 18.08:16 Till Kamppeter a écrit :
> > I have released cups-filters 1.2.0 now, with the following changes:
> >
> > - cups-browsed: When using IP-address-based device URIs via the
> > "IPBasedDeviceURIs" directive in cups-browsed.conf, add two additional
> > settings to restrict the used IP addresses to either only IPv4
> > addresses or only IPv6 addresses.
> > - foomatic-rip: SECURITY FIX: Also consider the back tick ('`') as an
> > illegal shell escape character. Thanks to Michal Kowalczyk from the
> > Google Security Team for the hint (CVE-2015-8327).
>
> Uploaded, thanks!
>
> I'm hereby CC'ing the security team to discuss the backport of that
> security fix (patch CC'ed) to jessie-security. At this stage, I don't
> have more details than the above, can you share more Till?
Thanks! Please upload to security-master. I'll take care of the DSA.
cups-filters from wheezy doesn't have foomatic-rip, is that in a different
source package or not present at all?
Cheers,
Moritz
Reply to: