cups-2.2.6-62.el8_10

エラータID: AXSA:2025-9531:01

Release date: 
Thursday, January 9, 2025 - 15:04
Subject: 
cups-2.2.6-62.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Low
Description: 

The Common UNIX Printing System (CUPS) provides a portable printing layer for Linux, UNIX, and similar operating systems.

Security Fix(es):

* cups: libppd: remote command injection via attacker controlled data in PPD file (CVE-2024-47175)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-47175
CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP attributes when creating the PPD buffer. When used in combination with other functions such as `cfGetPrinterAttributes5`, can result in user controlled input and ultimately code execution via Foomatic. This vulnerability can be part of an exploit chain leading to remote code execution (RCE), as described in CVE-2024-47176.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. cups-2.2.6-62.el8_10.src.rpm
    MD5: f735d8a77f6428443ce531dc12b2acde
    SHA-256: ecfbb6ce717dcec95f219713cbeb00c1466359bc948bffa42fe869b425c57e5a
    Size: 10.10 MB

Asianux Server 8 for x86_64
  1. cups-2.2.6-62.el8_10.x86_64.rpm
    MD5: 1db18c4345cfb13cef77e229c84dc078
    SHA-256: 6437c70f12c2c9109c8535f8f17cf1bc8994391a33a875be5402a6e7197ef374
    Size: 1.43 MB
  2. cups-client-2.2.6-62.el8_10.x86_64.rpm
    MD5: 01731b91244217687c9c306fd4f5c491
    SHA-256: 9c39cdb38d93a90dba64b5bde4a0af63a7c871c76cb49cbf637e1bc821450664
    Size: 172.36 kB
  3. cups-devel-2.2.6-62.el8_10.i686.rpm
    MD5: b7607296a8aa132632e4b3f37ed895f6
    SHA-256: 15c385a71359ce024a9ca5a5fb13f6f6029b743b13c3842e47b100e5db6f0042
    Size: 151.77 kB
  4. cups-devel-2.2.6-62.el8_10.x86_64.rpm
    MD5: f2e382b4d7a668bf832339d00a23ebb4
    SHA-256: 1bfd8f0688295d3f530a1d795693cffab02d927a4173a5a95c9d718093bc93db
    Size: 151.78 kB
  5. cups-filesystem-2.2.6-62.el8_10.noarch.rpm
    MD5: 6fc2ed7e86e59a1ad0b323529c6a5a99
    SHA-256: 09e5945de09b72afc4d1c2a0a54b47fccc40016d1a2a7c47805de12340394443
    Size: 112.11 kB
  6. cups-ipptool-2.2.6-62.el8_10.x86_64.rpm
    MD5: c5dd48ff350a5cd2d87bdfda45936c18
    SHA-256: b6e4f24085c1634b2fdfe931e0b88532f8edf9ce86fff24fe8a3c18d7a424073
    Size: 5.82 MB
  7. cups-libs-2.2.6-62.el8_10.i686.rpm
    MD5: 0a54843662a5b381e0c968e60ee9f8a4
    SHA-256: b1a13bcdd56d44aaa6c92551f87153be19d1b78a0011edb912be535713928e52
    Size: 462.91 kB
  8. cups-libs-2.2.6-62.el8_10.x86_64.rpm
    MD5: 0263a19789904215e74a0d3be342c24b
    SHA-256: edc7e18954325c5186b88ee2acdcad7c907452fda7063a9bea5611abec7ea61f
    Size: 436.43 kB
  9. cups-lpd-2.2.6-62.el8_10.x86_64.rpm
    MD5: 9b5008451efc46a8a536157832ef8b22
    SHA-256: 27a864718c82564f67bef1bf584c9d395d3206afac8dcb8f0e22db79050b1350
    Size: 127.39 kB