Home > Security > Advisories

Advisories

Mandriva Advisories

Package name cups
Date February 22nd, 2001
Advisory ID MDKSA-2001:023
Affected versions 7.2
Synopsis Updated cups packages fix a number of security issues

Problem Description

A number of problems were found by the SuSE security team recently
during an internal audit of the CUPS printing package. These problems
have been resolved with the latest CUPS release which include temp
file creation vulnerabilities, potential buffer overflows, and other
security enhancements. It is highly recommended that all
Linux-Mandrake users upgrade to this new version of CUPS. Due to prior
packaging problems, users are advised to completely remove the
following CUPS packages if they are currently installed on your system:

cups-common
libcups1
libcups1-devel

You can do this by using "rpm -e [package] --nodeps" for each package.
Once that is complete, you can upgrade CUPS using MandrakeUpdate.

Updated Packages

Mandrakelinux 7.2

 706b2bd00f2d7087e67d9049a256686c  7.2/RPMS/cups-1.1.6-10.1mdk.i586.rpm
b61f19494cb94a322e603ba5f6c5d840  7.2/RPMS/cups-devel-1.1.6-10.1mdk.i586.rpm
f29fc2472c406eca76eebf64fde0f3d4  7.2/SRPMS/cups-1.1.6-10.1mdk.src.rpm

Upgrade

To upgrade automatically, use MandrivaUpdate.


Verification

Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :

                rpm --checksig package.rpm
                

You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.

If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.