New Debian cups 2.2.1-8+deb9u7A~4.4.8.202111011209 fixes: This update addresses the following issue: * access to uninitialized buffer in ipp.c (CVE-2020-10001)
--- mirror/ftp/4.4/unmaintained/4.4-6/source/cups_2.2.1-8+deb9u6A~4.4.5.202007221413.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/cups_2.2.1-8+deb9u7A~4.4.8.202111011209.dsc @@ -1,4 +1,4 @@ -2.2.1-8+deb9u6A~4.4.5.202007221413 [Wed, 22 Jul 2020 14:24:39 +0200] Univention builddaemon <buildd@univention.de>: +2.2.1-8+deb9u7A~4.4.8.202111011209 [Mon, 01 Nov 2021 12:16:45 +0100] Univention builddaemon <buildd@univention.de>: * UCS auto build. The following patches have been applied to the original source package 00-autostart-setting @@ -9,6 +9,13 @@ 15_postponed-univention-lpadmin-systemd 20_no-on-demand-systemd-service +2.2.1-8+deb9u7 [Fri, 29 Oct 2021 22:03:02 +0200] Thorsten Alteholz <debian@alteholz.de>: + + * Non-maintainer upload by the LTS Team. + * CVE-2020-10001.patch + An input validation issue might allow a malicious application + to read restricted memory. + 2.2.1-8+deb9u6 [Mon, 27 Apr 2020 08:50:13 +0200] Didier Raboud <odyx@debian.org>: * Backport upstream security fixes: <http://piuparts.knut.univention.de/4.4-8/#384430287677880064>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-8] 5f6fc8ce68 Bug #54003: cups 2.2.1-8+deb9u7A~4.4.8.202111011209 doc/errata/staging/cups.yaml | 12 ++++++++++++ 1 file changed, 12 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x1080>