[CLSA-2026:1787304093] Fix CVE(s): CVE-2024-47175, CVE-2024-47176
Type:
security
Severity:
Critical
Release date:
2026-08-21 09:21:43 UTC
Description:
* SECURITY UPDATE: PPD injection through unvalidated IPP attributes in the PPD generator (ELSCVE-171480) - debian/patches/CVE-2024-47175.patch: sanitize the make and model, gate every IPP string written into the generated PPD on ippValidateAttribute(), and restrict PPD keywords to a safe character set in cupsfilters/ppdgenerator.c. - CVE-2024-47175 * SECURITY UPDATE: cups-browsed creates print queues from unauthenticated packets on UDP port 631 (ELSCVE-171473) - debian/patches/CVE-2024-47176.patch: drop "cups" from the default BrowseRemoteProtocols in configure.ac, so the legacy CUPS browsing listener is not enabled. - CVE-2024-47176
Updated packages:
  • cups-browsed_1.20.2-0ubuntu3.3+tuxcare.els1_amd64.deb
    sha:55c7e58a3ae708e971c8006a75f1ff38c2605c3c
  • cups-filters_1.20.2-0ubuntu3.3+tuxcare.els1_amd64.deb
    sha:847dcaddd6d397cc0f97c6d6875e9c97444ebfda
  • cups-filters-core-drivers_1.20.2-0ubuntu3.3+tuxcare.els1_amd64.deb
    sha:779faec56d92ccf1b036efeddab32245b1ad8500
  • libcupsfilters-dev_1.20.2-0ubuntu3.3+tuxcare.els1_amd64.deb
    sha:4a2a4288dc38a4d0d854af5a76af7c187e3af3d3
  • libcupsfilters1_1.20.2-0ubuntu3.3+tuxcare.els1_amd64.deb
    sha:3ddefcbfd83092b49a7fba9b55af143c471c5e5c
  • libfontembed-dev_1.20.2-0ubuntu3.3+tuxcare.els1_amd64.deb
    sha:8f3d713b8d60f385a6649e4b83364b64d2fd1c43
  • libfontembed1_1.20.2-0ubuntu3.3+tuxcare.els1_amd64.deb
    sha:a0a2d8f08d740c106a4eda1da1fe9307aeaedd40
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.