-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5778-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso September 29, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : cups-filters CVE ID : CVE-2024-47076 CVE-2024-47176 Debian Bug : 1082820 1082827 Simone Margaritelli reported several vulnerabilities in cups-filters. Missing validation of IPP attributes returned from an IPP server and multiple bugs in the cups-browsed component can result in the execution of arbitrary commands without authentication when a print job is started. For the stable distribution (bookworm), these problems have been fixed in version 1.28.17-3+deb12u1. We recommend that you upgrade your cups-filters packages. For the detailed security status of cups-filters please refer to its security tracker page at: https://security-tracker.debian.org/tracker/cups-filters Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmb5b6BfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0RqGA//VfGe41guaMVg8lIgwu9s3atSUeoUDZRf83XWQ0S6gvpTCG/Bko1KSgj0 xmzHlmjwFA2Sly5PhiWcqDp59txdXZymdojTXFebuE5MFqxcSLoIpn/vxZT6f3ky BdfK4oTXfJ5Au+KgRF+jC9zGiKgkMJfaCaf2PPFwan/4nXLYw/GIkvnYAecjGgEQ KjuzUgkItBVaGVeaInMISwfSISQFrMK80P7MJyX8ET2b71ijjpReAbfsuOQRaizj 5dnBXxCAE8l8A5VsZFUT1EK4m3Z7BgKKImnLqDdk61Mz+T7eC4R+Kv+rb5lLBMYK pPuBmYlH80U7bK4/TaivuWrX6FdHvtKGFUmQd+YO6rWofwrCTn/8+SlO8ZWOrjKx r7UDU7+XTnCu4DI87+7PBcqHEyQTG3CrK/RKblsfw0PP0DFtwJMiipuSjzBmNRZx nZppuug7Ks5dljAYGWFrBx2I29Qtj6MD4HeI4JKWoB3r3Xi1gX5vvsav4/r++s9Z GvINaqBBIytLjATxLYElCxA74MEmVFNPxUEeEq8xFyPGdnYquJ6xZ6wsy6x+O6Z2 T4ikIV5+FUA4v/c9JFdMj04dJXXaIfTcxBvYA4CoykdHmMGAw1/rCuucL4zoPMUl G03rz0k3/QziqZ6EM/Firbd++RrCo86wBiA10Anmhy7+0kS3TCE= =fH4o -----END PGP SIGNATURE-----