New Debian cups 2.4.2-3+deb12u9A~5.2.3.202509151048 fixes: This update addresses the following issues: 2.4.2-3+deb12u9 (Sun, 07 Sep 2025 19:45:05 +0200) * CVE-2025-58060 fix authentication bypass with AuthType Negotiate * CVE-2025-58364 fix remote DoS via null dereference
--- mirror/ftp/pool/main/c/cups/cups_2.4.2-3+deb12u8A~5.2.0.202501091036.dsc +++ apt/ucs_5.2-0-errata5.2-3/source/cups_2.4.2-3+deb12u9A~5.2.3.202509151048.dsc @@ -1,4 +1,4 @@ -2.4.2-3+deb12u8A~5.2.0.202501091036 [Thu, 09 Jan 2025 10:36:40 -0000] Univention builddaemon <buildd@univention.de>: +2.4.2-3+deb12u9A~5.2.3.202509151048 [Mon, 15 Sep 2025 10:48:46 -0000] Univention builddaemon <buildd@univention.de>: * UCS auto build. The following patches have been applied to the original source package 01-do-not-set-auth-info-automatically.quilt @@ -7,6 +7,13 @@ 11_cups-disable-test.quilt 15_postponed-univention-lpadmin-systemd.quilt 20_no-on-demand-systemd-service.quilt + +2.4.2-3+deb12u9 [Sun, 07 Sep 2025 19:45:05 +0200] Thorsten Alteholz <debian@alteholz.de>: + + * CVE-2025-58060 + fix authentication bypass with AuthType Negotiate + * CVE-2025-58364 + fix remote DoS via null dereference 2.4.2-3+deb12u8 [Thu, 26 Sep 2024 23:45:05 +0200] Thorsten Alteholz <debian@alteholz.de>: <http://piuparts.knut.univention.de/5.2-3/#7841449854244797421>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-3] 20eeee8c1f Bug #58641: cups 2.4.2-3+deb12u9A~5.2.3.202509151048 doc/errata/staging/cups.yaml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x187>