New Debian cups 2.2.10-6+deb10u11A~5.0.9.202410071504 fixes: This update addresses the following issues: 2.2.10-6+deb10u11 (Thu, 26 Sep 2024 23:45:05 +0200) * CVE-2024-47175 Fix CVE and upstream also added some extra hardening to patch - validate response from printer in scheduler/ipp.c - sanitize make and model in cups/ppd-cache.c - PPDize preset and template names in cups/ppd-cache.c * fix possible regression of CVE-2024-35235 in case only domain sockets are used
--- mirror/ftp/pool/main/c/cups/cups_2.2.10-6+deb10u10A~5.0.8.202406130955.dsc +++ apt/ucs_5.0-0-errata5.0-9/source/cups_2.2.10-6+deb10u11A~5.0.9.202410071504.dsc @@ -1,4 +1,4 @@ -2.2.10-6+deb10u10A~5.0.8.202406130955 [Thu, 13 Jun 2024 09:56:02 -0000] Univention builddaemon <buildd@univention.de>: +2.2.10-6+deb10u11A~5.0.9.202410071504 [Mon, 07 Oct 2024 15:05:24 -0000] Univention builddaemon <buildd@univention.de>: * UCS auto build. The following patches have been applied to the original source package 01-do-not-set-auth-info-automatically.quilt @@ -9,6 +9,16 @@ 20_no-on-demand-systemd-service.quilt 25-true-is-case-sensitive-in-ppds.quilt +2.2.10-6+deb10u11 [Thu, 26 Sep 2024 23:45:05 +0200] Thorsten Alteholz <debian@alteholz.de>: + + * CVE-2024-47175 + Fix CVE and upstream also added some extra hardening to patch + - validate response from printer in scheduler/ipp.c + - sanitize make and model in cups/ppd-cache.c + - PPDize preset and template names in cups/ppd-cache.c + * fix possible regression of CVE-2024-35235 in case only domain sockets + are used + 2.2.10-6+deb10u10 [Tue, 11 Jun 2024 22:16:49 +0200] Thorsten Alteholz <debian@alteholz.de>: * CVE-2024-35235 <http://piuparts.knut.univention.de/5.0-9/#5286454264934237070>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.0-9] 20d5b74b8b Bug #57647: cups 2.2.10-6+deb10u11A~5.0.9.202410071504 doc/errata/staging/cups.yaml | 12 +++++------- 1 file changed, 5 insertions(+), 7 deletions(-) [5.0-9] 6103de394e Bug #57647: cups 2.2.10-6+deb10u11A~5.0.9.202410071504 doc/errata/staging/cups.yaml | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x1134>