Release date:
2026-08-21 09:21:43 UTC
Description:
* SECURITY UPDATE: PPD injection through unvalidated IPP attributes in the
PPD generator (ELSCVE-171480)
- debian/patches/CVE-2024-47175.patch: sanitize the make and model, gate
every IPP string written into the generated PPD on
ippValidateAttribute(), and restrict PPD keywords to a safe character
set in cupsfilters/ppdgenerator.c.
- CVE-2024-47175
* SECURITY UPDATE: cups-browsed creates print queues from unauthenticated
packets on UDP port 631 (ELSCVE-171473)
- debian/patches/CVE-2024-47176.patch: drop "cups" from the default
BrowseRemoteProtocols in configure.ac, so the legacy CUPS browsing
listener is not enabled.
- CVE-2024-47176
Updated packages:
-
cups-browsed_1.20.2-0ubuntu3.3+tuxcare.els1_amd64.deb
sha:55c7e58a3ae708e971c8006a75f1ff38c2605c3c
-
cups-filters_1.20.2-0ubuntu3.3+tuxcare.els1_amd64.deb
sha:847dcaddd6d397cc0f97c6d6875e9c97444ebfda
-
cups-filters-core-drivers_1.20.2-0ubuntu3.3+tuxcare.els1_amd64.deb
sha:779faec56d92ccf1b036efeddab32245b1ad8500
-
libcupsfilters-dev_1.20.2-0ubuntu3.3+tuxcare.els1_amd64.deb
sha:4a2a4288dc38a4d0d854af5a76af7c187e3af3d3
-
libcupsfilters1_1.20.2-0ubuntu3.3+tuxcare.els1_amd64.deb
sha:3ddefcbfd83092b49a7fba9b55af143c471c5e5c
-
libfontembed-dev_1.20.2-0ubuntu3.3+tuxcare.els1_amd64.deb
sha:8f3d713b8d60f385a6649e4b83364b64d2fd1c43
-
libfontembed1_1.20.2-0ubuntu3.3+tuxcare.els1_amd64.deb
sha:a0a2d8f08d740c106a4eda1da1fe9307aeaedd40
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.